GHDB « Hackers For Charity

GHDB

GHDB

Google Search: “delete entries” inurl:admin/delete.asp

FiZiX rates this entry 7 out of 10.
Submitted: 2005-02-17 00:00:00
Added by: FiZiX
Hits: 10606
Score: 7

As described in OSVDB article #13715:”AspJar contains a flaw that may allow a malicious user to delete arbitrary messages. The issue is triggered when the authentication method is bypassed and /admin/delete.asp is accessed directly. It is possible that the flaw may allow a malicious user to delete messages resulting in a loss of integrity.”The company supporting this software is no longer in business and the software is no longer being updated. Therefore, versions should not matter in this dork.


Comments:

2005-03-11 02:32:02 (donjoe145): most links i found were defaced

2005-03-24 11:34:27 (zoidberg): http://www.remshot.com/guestbook/admin/delete.asp

First match on the google list

Hacked by O ^|^ W

eak!


2005-03-26 01:43:12 (Twizik): wow i went to the likn above^^ and i looked at the source and it appears all the messages that were in the guestbook are still there so could someone explain to me how he wrote his/her name on the page and cover up the guestbook???

2005-08-16 21:58:06 (DaJacks): To the question above. He used the tags around the html code.


5 Responses to “GHDB”

  1. Jack says:

    Does GHDB still updates for now?

  2. Johnny says:

    The GHDB is alive and well, updated through the ExploitDB: http://www.exploit-db.com/google-dorks.

  3. The Artist says:

    Hi Johnny,been a while since I’ve came last. Aren’t you gonna update this website anymore???

  4. Johnny says:

    The GHDB is not updated and lives with the exploitdb: http://http://www.exploit-db.com. Please check out the awesome folks at Offensive Security as well: http://www.offensive-security.com!

  5. Velmurugan says:

    Is any offline view-able resources is available of this product ?

Leave a Reply