|
Google Search: intitle:guestbook “advanced guestbook 2.2 powered”
ThrowedOff rates this entry 6 out of 10. Advanced Guestbook v2.2 has an SQL injection problem which allows unauthorized access. AttackerFrom there, hit “Admin” then do the following:Leave username field blank.For password, enter this exactly:’) OR (‘a’ = ‘aYou are now in the Guestbook’s Admin section.http://www.securityfocus.com/bid/10209 Comments: 2004-05-27 18:29:44 (Anonymous): 2004-05-30 09:53:12 (Fr0zen): 2004-12-25 10:51:00 (vinny): I search i google ? then exampl: and i get an error Access Denied ? Wat i doing wrong ? 2005-08-18 20:43:18 (JTR000): |
