Code Widget Database Driven Product Catalogue (ASP) SQL Injection
PHP:
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 Â Â _ Â Â Â Â Â Â Â Â Â __ Â Â Â Â Â __ Â Â Â __ Â Â Â Â Â Â Â Â Â Â 1
1 Â /' \ Â Â Â Â Â Â __ Â /'__`\ Â Â Â Â /\ \__ Â /'__`\ Â Â Â Â Â Â Â Â Â 0
0 Â /\_, \ Â Â ___ Â /\_\/\_\ \ \ Â Â ___\ \ ,_\/\ \/\ \ Â _ ___ Â Â Â Â Â 1
1 Â \/_/\ \ /' _ `\ \/\ \/_/_\_<_ Â /'___\ \ \/\ \ \ \ \/\`'__\ Â Â Â Â Â 0
0 Â Â \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/ Â Â Â Â Â 1
1 Â Â Â \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\ Â Â Â Â Â 0
0 Â Â Â \/_/\/_/\/_/\ \_\ \/___/ Â \/____/ \/__/ \/___/ Â \/_/ Â Â Â Â Â 1
1          \ \____/ >> Exploit database separated by exploit  0
0 Â Â Â Â Â Â Â Â Â \/___/ Â Â Â Â Â type (local, remote, DoS, etc.) Â Â 1
1 Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â 1
0  [+] Site       :  1337day.com                  0
1           inj3ct0r 1337 Day Team              1
0 Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â 0
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1
Author: L0rd CrusAd3r aka VSN [[email protected]]
Exploit Title: Code Widget Database Driven Product Catalogue (ASP) SQl Injection Vulnerability
Vendor url:http://www.comriesoftware.net/codewidgets/product.aspx?key=60
Published: 17-August-2011
Greetz to:r0073r (1337day.com), r4dc0re, Sid3^effects,See Me, Awesomeness, Sonic Bluehat.
Special Greetz: inj3ct0r Team
Shoutzz:- To all My hacker friends
Price:18$ Â PS: This is not the cost of the Exploit but Cost of the Product..Information for n00bs alone
~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*
Description:
Active Server Pages Product Catalogue with ADO recordset paging
Page content stored in database.
Includes all Source Code, Database and Demo.
Complete Front Page 2000 web file
~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*
Vulnerability:
*SQl injection Vulnerability
DEMO URL: http://www.codewidgets.net/CS0060/item.asp?key=[sqli]
# 0day n0 m0re #
# L0rd CrusAd3r #
# Â 0day.today [2017-11-14] Â #
