AOH :: HP Unsorted A :: B06-4543.HTM

Autentificator <=2.01 SQL Injection Vulnerability



Autentificator <=2.01 SQL Injection Vulnerability
Autentificator <=2.01 SQL Injection Vulnerability



Discovered by Sirdarckcat from elhacker.net
------------------------------------------------------------------------------------

Autentificator v2.01 SQL Injection
http://www.hotscripts.com/Detailed/15291.html

------------------------------------------------------------------------------------

Autentificator is a simple PHP based program for
helping administrators to controll access to certain
pages.

It suffers of a SQL Injection vulnerability.

------------------------------------------------------------------------------------

PoC:

http://autentificator/aut_verifica.inc.php
POST DATA:
user='+[SQL]&pass=something

------------------------------------------------------------------------------------

Att.
Sirdarckcat
elhacker.net

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.