Exploit CyberStrong EShop 4.2 - '20review.asp' SQL Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
25922
Проверка EDB
  1. Пройдено
Автор
[email protected]
Тип уязвимости
WEBAPPS
Платформа
ASP
CVE
cve-2003-0509
Дата публикации
2005-06-30
Код:
source: https://www.securityfocus.com/bid/14101/info

CyberStrong eShop is prone to an SQL-injection vulnerability. As a result, the attacker may modify the structure and logic of an SQL query that is made by the application. The attacker may accomplish this by passing malicious SQL syntax to the vulnerable '20review.asp' script.

Reportedly, the attacker may steal eShop authentication information. Other attacks may be possible, depending on the capabilities of the underlying database and the nature of the affected query.

http://www.example.com/eshop/20Review.asp?ProductCode='
 
Источник
www.exploit-db.com