Visit our newest sister site!
Hundreds of free aircraft flight manuals
Civilian • Historical • Military • Declassified • FREE!

TUCoPS :: Web :: Apps :: b06-1244.htm

DSLogin Authentication Bypass Vulnerability
DSLogin Authentication Bypass Vulnerability
DSLogin Authentication Bypass Vulnerability

New eVuln Advisory:
DSLogin Authentication Bypass Vulnerability 

eVuln ID: EV0100
CVE: CVE-2006-1238
Software: DSLogin
Sowtware's Web Site: 
Versions: 1.0
Critical Level: Moderate
Type: SQL Injection
Class: Remote
Status: Unpatched. No reply from developer(s)
PoC/Exploit: Not Available
Solution: Not Available
Discovered by: Aliaksandr Hartsuyeu (

Vulnerable scripts:

Variable $log_userid isn't properly sanitized before being used in SQL query. This can be used to bypass authentication using SQL injection and make any SQL query by injecting arbitrary SQL code.

Condition: magic_quotes_gpc = off

Waiting for developer(s) reply.
If there is no reply exploitation code will be published in 10 days 

No Patch available.

Discovered by: Aliaksandr Hartsuyeu (

Aliaksandr Hartsuyeu - Penetration Testing Services 

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2015 AOH