TUCoPS :: HP Unsorted A :: b06-4543.htm

Autentificator <=2.01 SQL Injection Vulnerability
Autentificator <=2.01 SQL Injection Vulnerability
Autentificator <=2.01 SQL Injection Vulnerability



Discovered by Sirdarckcat from elhacker.net
------------------------------------------------------------------------------------

Autentificator v2.01 SQL Injection
http://www.hotscripts.com/Detailed/15291.html

------------------------------------------------------------------------------------

Autentificator is a simple PHP based program for
helping administrators to controll access to certain
pages.

It suffers of a SQL Injection vulnerability.

------------------------------------------------------------------------------------

PoC:

http://autentificator/aut_verifica.inc.php
POST DATA:
user='+[SQL]&pass=something

------------------------------------------------------------------------------------

Att.
Sirdarckcat
elhacker.net

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH