header-logo
Suggest Exploit
vendor:
MCLogin System
by:
L0rd CrusAd3r
8,8
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: MCLogin System
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010

Authentication Bypass in Home of MCLogin System

With MCLogin System your visitors can login or register a new account. It is written in PHP and the data is stored in a MySql database.Very easy to install or to customize to meet your needs. You can add it to your pages with just one link. The Provided Script as Sqli Vulnerability in Admin Login page. Use the string a' or '1'='1 for Username and Password to gain access.

Mitigation:

Ensure that authentication credentials are properly validated and that user input is properly sanitized.
Source

Exploit-DB raw data:

Author: L0rd CrusAd3r
Published: 2010-06-08
Vendor url:-/www.maniacomputer.com
################################################################################################

Authentication Bypass in Home of MCLogin System
1,1
######################################Author:L0rd
CrusAd3r######################################

Description:-

With MCLogin System your visitors can login or register a new account. It is
written in PHP and the data is stored in a MySql database.Very easy to
install or to customize to meet your needs. You can add it to your pages
with just one link.

###################################################################################################

Vulnerability:-

*Authentication Bypass found

The Provided Script as Sqli Vulnerability in Admin Login page

DEMO : http://server/login/login_index.php

Use the string a' or '1'='1 for Username and Password to gain access.

######################################################################################################


Greetz to:MaYur,Sid3^effects

-- 
With R3gards,
L0rd ÇrusAdêr