BugTraq
ASPjar Guestbook login.asp not official patch Feb 15 2005 04:03PM
CorryL (corryl sitoverde com)
..::x0n3-h4ck.org Italian Security Team::..

ASPjar Guestbook login.asp not official patch

Application: Aspjar Guestbook
Version: 1.0
Bug: Sqj injection
Vendor : not attainable

DETAILS

Supply in the password field ' or ''=', this should allow you to bypass
the authentication process used by ASPjar Guestbook.

Patch:

This is patch created by Expanders from x0n3-h4ck Italian Security Team.

Find in the file admin\login.asp this is string:

strSql ="SELECT * from admin where Name = '" & Request.Form("User") & "' and
password = '" & Request.Form("Password") &"'"

you replace with:

strSql ="SELECT * from admin where Name = '" &
replace(Request.Form("User"),"'","") & "' and password = '" &
replace(Request.Form ("Password"),"'","") &"'"

For Info www.x0n3-h4ck.org

CorryL

corryl80 (at) gmail (dot) com [email concealed]

www.x0n3-h4ck.org

_________________________________
www.seekstat.it is your web stat

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus