|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
[Full-Disclosure] ASPjar Guestbook login.asp not official patch
From: CorryL (corryl
sitoverde.com)
Date: Mon Feb 14 2005 - 10:58:02 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
..::x0n3-h4ck.org Italian Security Team::..
ASPjar Guestbook login.asp not official patch
Application: Aspjar Guestbook
Version: 1.0
Bug: Sqj injection
Vendor : not attainable
DETAILS
Supply in the password field ' or ''=', this should allow you to bypass
the authentication process used by ASPjar Guestbook.
Patch:
This is patch created by Expanders from x0n3-h4ck Italian Security Team.
Find in the file admin\login.asp this is string:
strSql ="SELECT * from admin where Name = '" & Request.Form("User") & "' and
password = '" & Request.Form("Password") &"'"
you replace with:
strSql ="SELECT * from admin where Name = '" &
replace(Request.Form("User"),"'","") & "' and password = '" &
replace(Request.Form ("Password"),"'","") &"'"
For Info www.x0n3-h4ck.org
CorryL
corryl80
gmail.com
www.x0n3-h4ck.org
_________________________________
www.seekstat.it is your web stat
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]