Wednesday, February 23, 2011

SQL and XSS in DIY Web CMS

SQL and XSS in DIY Web CMS

found by : p0pc0rn 22/2/2011
web : http://www.mydiyweb.com.my
dork : intext:"powered by DiyWeb"

SQL - Microsoft JET Database Engine error
-----------------------------------------

http://site.com/template.asp?menuid=[SQL]
http://site.com/viewcatalog.asp?id=[SQL]
http://site.com/xxx.asp?id=[SQL]

XSS
---
http://site.com/diyweb/login.asp?msg=[XSS] -- login page



http://www.exploit-db.com/exploits/16205/

thanks
-p0pc0rn-
Share:

0 comments: