A Henry P. Erich III Blog

A Geek In and Around Orlando

<December 2008>
SuMoTuWeThFrSa
30123456
78910111213
14151617181920
21222324252627
28293031123
45678910


Navigation

Links

Subscriptions



Thursday, April 22, 2004 - Posts

Another Reason I Love A9 - Search By URL (Part 2)

Earlier today I found a SQL Injection Vuln for Guestbook 2.2, so I searched for this via A9

a9.com/guestbook%202.2 (the %20 is the same thing as a space in an URL)

I decided to go to page 26 (135,000 results) and after clicking a page number on the bottom I notice the URL is http://a9.com/guestbook%202.2?p=26.

Awesome, the ?p= is how to tell it a page!


OK, so you dont care about searching by URL, but you think the vuln is interesting?

...after clicking the admin link, leave the username blank and put ') OR ('a' = 'a in the password field.

 

posted Thursday, April 22, 2004 10:23 AM by he3 with 0 Comments




Powered by Dot Net Junkies, by Telligent Systems