Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
BellaBiblio Admin Login Bypass Jul 30 2007 07:29PM
ilkerkandemir mynet com
BellaBiblio Admin Login Bypass

SCRIPT: BellaBiblio

DOWNLOAD: http://www.jemjabella.co.uk/scripts/BellaBiblio.zip

AUTHOR: ilker kandemir <ilkerkandemir[at]mynet.com>

Bug in;(admin.php)
if (isset($_COOKIE['bellabiblio'])) {
if ($_COOKIE['bellabiblio'] == md5($admin_name.$admin_pass.$secret)) {...

[ more ]  





 

Privacy Statement
Copyright 2008, SecurityFocus