|
|
| |
| Spooky Login offers the ability to create a login system to restrict access to certain pages, or a powerful registration system for your whole site. A security vulnerability in the product allows attackers to insert malicious SQL code into the login procedure thus circumventing the authentication mechanism. |
| |
Credit:
The information has been provided by Derek Hinch.
|
| |
Vulnerable systems:
Spooky Login version 2.5 and prior
Exploit:
User: admin (this selects the first index from the table)
Password: ' OR ''='
Vendor status:
The vendor has been notified and a fix has been issued.
|
| Subject:
|
Product Has Been Discontinued as a Result |
Date: |
7 Jan. 2009 |
| From: |
derek d0t h1nch at gma1L.c0m |
| This product only existed to the vendor's last release. It was discontinued due to the bug and the inability to support the customers who purchased the library and others that purchased its source. Please view the vendors website to obtain support information. You can reach the vendor and view a product history at www dot spookylogin dot com. |
|
|
|
|