[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20070211123726.17692.qmail@securityfocus.com>
Date: 11 Feb 2007 12:37:26 -0000
From: crazy_king@...7.org
To: bugtraq@...urityfocus.com
Subject: KvGuestbook Remote Add Admin Exploit
Version : 1.0 Beta
Download : http://www.killervault.com
Files : guestbook.php
Error : function dologin() {
global $mysql, $gbpass, $gburl;
$time = time() + 86400*365;
if($gbpass == $mysql['pass']) {
setcookie('kvgbcookie', $mysql['pass'], $time, '/');
}
header("Location: $gburl");
}
$mysql, $gbpass, $gburl
Mysql & Admin Pass & Admin Name
Powered by blists - more mailing lists