vendor:
al3jeb script
by:
cr4wl3r
5.5
CVSS
MEDIUM
Remote Login Bypass
287
CWE
Product Name: al3jeb script
Affected Version From: Not specified
Affected Version To: Not specified
Patch Exists: No
Related CWE:
CPE: Not specified
Platforms Tested: Not specified
2010
al3jeb script Remote Login Bypass Exploit
This exploit allows bypassing the remote login functionality in the al3jeb script. It only works when magic_quotes_gpc is turned off. The vulnerability exists in the login.php file, where user input is not properly sanitized before being used in a SQL query, allowing an attacker to log in without a valid username and password combination.
Mitigation:
To mitigate this vulnerability, enable magic_quotes_gpc or use proper input validation and parameterized queries to prevent SQL injection.