exploit-db-mirror/exploits/asp/webapps/16205.txt
Offensive Security 36c084c351 DB: 2021-09-03
45419 changes to exploits/shellcodes

2 new exploits/shellcodes

Too many to list!
2021-09-03 13:39:06 +00:00

15 lines
No EOL
390 B
Text

SQL and XSS in DIY Web CMS
found by : p0pc0rn 22/2/2011
web : http://www.mydiyweb.com.my
dork : intext:"powered by DiyWeb"
SQL - Microsoft JET Database Engine error
-----------------------------------------
http://site.com/template.asp?menuid=[SQL]
http://site.com/viewcatalog.asp?id=[SQL]
http://site.com/xxx.asp?id=[SQL]
XSS
---
http://site.com/diyweb/login.asp?msg=[XSS] -- login page