Google Dork Description: intitle:guestbook "advanced guestbook 2.2 powered" | GHDB-ID: 225 |
Google Search: intitle:guestbook "advanced guestbook 2.2 powered" | EDB-ID: N/A |
Published: | Author: anonymous |
Advanced Guestbook v2.2 has an SQL injection problem which allows unauthorized access. AttackerFrom there, hit "Admin" then do the following:Leave username field blank.For password, enter this exactly:') OR ('a' = 'aYou are now in the Guestbook's Admin section.http://www.securityfocus.com/bid/10209