[NT] RealityScape MyLogin 2000 Professional SQL Injection
From: support@securiteam.comDate: 05/06/02
- Previous message: support@securiteam.com: "[UNIX] B2 PHP Remote Command Execution"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Date: Mon, 6 May 2002 19:40:10 +0200 (CEST)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -
RealityScape MyLogin 2000 Professional SQL Injection
------------------------------------------------------------------------
SUMMARY
<http://www.hotscripts.com/Detailed/6819.html> MyLogin 2000 is a server
side DLL component that allows you to authenticate and maintain users for
your site. The product has been found to contain a security vulnerability
that would allow a remote attacker to bypass its username and password
protection.
DETAILS
Vulnerable systems:
RealityScape MyLogin 2000 version 1.0.0
Vendor response:
The product has been discontinued.
Solution:
Consider using other products instead of this one.
Exploit:
Input the following values into your logon screen:
Username: ' OR ''='
Password: ' OR ''='
You should be able to now enter as the first username record in the
database.
ADDITIONAL INFORMATION
The information has been provided by <mailto:derek@sybodek.com> Derek
Hinch.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: support@securiteam.com: "[UNIX] B2 PHP Remote Command Execution"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|