Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:16034
HistoryFeb 12, 2007 - 12:00 a.m.

KvGuestbook Remote Add Admin Exploit

2007-02-1200:00:00
vulners.com
22

Version : 1.0 Beta

Download : http://www.killervault.com

Files : guestbook.php

Error : function dologin() {
global $mysql, $gbpass, $gburl;
$time = time() + 86400*365;
if($gbpass == $mysql['pass']) {
setcookie('kvgbcookie', $mysql['pass'], $time, '/');
}
header("Location: $gburl");
}

$mysql, $gbpass, $gburl

Mysql & Admin Pass & Admin Name