Code Widget Multiple Question - Choice Online Questionaire SQL Injection
PHP:
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 Â Â _ Â Â Â Â Â Â Â Â Â __ Â Â Â Â Â __ Â Â Â __ Â Â Â Â Â Â Â Â Â Â 1
1 Â /' \ Â Â Â Â Â Â __ Â /'__`\ Â Â Â Â /\ \__ Â /'__`\ Â Â Â Â Â Â Â Â Â 0
0 Â /\_, \ Â Â ___ Â /\_\/\_\ \ \ Â Â ___\ \ ,_\/\ \/\ \ Â _ ___ Â Â Â Â Â 1
1 Â \/_/\ \ /' _ `\ \/\ \/_/_\_<_ Â /'___\ \ \/\ \ \ \ \/\`'__\ Â Â Â Â Â 0
0 Â Â \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/ Â Â Â Â Â 1
1 Â Â Â \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\ Â Â Â Â Â 0
0 Â Â Â \/_/\/_/\/_/\ \_\ \/___/ Â \/____/ \/__/ \/___/ Â \/_/ Â Â Â Â Â 1
1          \ \____/ >> Exploit database separated by exploit  0
0 Â Â Â Â Â Â Â Â Â \/___/ Â Â Â Â Â type (local, remote, DoS, etc.) Â Â 1
1 Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â 1
0  [+] Site       :  1337day.com                  0
1           inj3ct0r 1337 Day Team              1
0 Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â 0
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1
Author: L0rd CrusAd3r aka VSN [[email protected]]
Exploit Title: Code Widget Multiple Question - Multiple Choice Online Questionaire (ASP) SQL injection Vulnerability
Vendor url: http://www.comriesoftware.net/codewidgets/product.aspx?key=99
Published: 17-August-2011
Greetz to:r0073r (1337day.com), r4dc0re, Sid3^effects,See Me, Awesomeness, Sonic Bluehat.
Special Greetz: inj3ct0r Team
Shoutzz:- To all My hacker friends
Price:20$ Â PS: This is not the cost of the Exploit but Cost of the Product..Information for n00bs alone
~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*
Description:
Online Survey/Questionaire Web Application
Complete ASP Web File and Microsoft® Access Database
Questionaire info, Questions and Options/Answers are stored and retrieved from database.
The user pages through multiple questions and clicks on the desired answer, results are stored in a Microsoft® Access Database.
Can be used to collect stats or as a quiz engine.
~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*
Vulnerability:
*SQL injection Vulnerability
DEMO URL: http://www.codewidgets.net/CS0099/index.asp?Q=2&A=[sqli]
# 0day n0 m0re #
# L0rd CrusAd3r #
# Â 0day.today [2017-11-14] Â #
