Saturday, February 26, 2011

WebContent CMS Vulnerable to Multiple SQL Injection


Title : WebContent CMS Vulnerable to Multiple SQL Injection
Web : http://www.interbase.com.my/
Found by: p0pc0rn 26/02/2011
Dork
: intext:"Powered By Interbase WebContent"
: inurl:"cms/layout/Printer.asp?ProductID="
: intext:"Powered By WebContent"


SQL - Microsoft JET Database Engine
------------------------------------

http://site.com/cms/AllProduct.asp?CatID=[SQL]
http://site.com/cms/layout/Printer.asp?ProductID=[SQL]
http://site.com/cms/General.asp?ProductID=[SQL]



http://www.1337day.com/exploits/15513

thanks,
-p0pc0rn-
Share:

0 comments: