[*] Target: http://mazda-gh.tw/ [*] Operating System: Windows 2008 [*] Web Server: Microsoft IIS 7.5 [*] DBMS: Microsoft Access 2000 [*] Vulnerability: Blind SQL Injection [*] Author: D35m0nd142 [*] Database: Microsoft_Access_masterdb Database: Microsoft_Access_masterdb [5 tables] +---------+ | account | | admin | | product | | reguser | | setting | +---------+ Database: Microsoft_Access_masterdb Table: account [4 columns] +----------+-------------+ | Column | Type | +----------+-------------+ | account | non-numeric | | password | non-numeric | | poster | non-numeric | +----------+-------------+ Database: Microsoft_Access_masterdb Table: admin [4 columns] +----------+-------------+ | Column | Type | +----------+-------------+ | adminpwd | non-numeric | | adminuid | non-numeric | | id | numeric | | poster | non-numeric | +----------+-------------+ Database: Microsoft_Access_masterdb Table: account [1 entry] +--------+---------+----------+ | poster | account | password | +--------+---------+----------+ | MAZDA | adm | co##ter | +--------+---------+----------+ Database: Microsoft_Access_masterdb Table: admin [1 entry] +----+----------+--------+----------+ | id | adminuid | poster | adminpwd | +----+----------+--------+----------+ | 1 | admin | MAZDA | a##in | +----+----------+--------+----------+