关键信息 EDB-ID: 4824 CVE: 2007-6665 Author: GUGA360 Type: WEB APPS Platform: ASP Date: 2007-12-31 Vulnerable App: oneSCHOOL - 'admin/login.asp' exploit: Download / {} Vulnerable Version: All versions bug: SQL Injection Code Snippets: The provided exploit code is written in Python. The script includes: Description: oneSCHOOL admin/login.asp SQL Injection exploit for all versions How It Works: It grafts a UNION SQL injection that selects the user login and password fields from the 'UsersSecure' table to exploit the vulnerability and display the administrative credentials. Usage Instructions: It's straightforward to use with a single argument being the target host where the exploited application is running. Advisory/Source: Link