MyPHPSoft MyPHPLinks 2.1.9/2.2 - SQL Injection Administration Bypassing

EDB-ID:

22088


Author:

frog

Type:

webapps


Platform:

PHP

Date:

2002-12-14


source: https://www.securityfocus.com/bid/6395/info

MyPHPLinks is a freely available, open source PHP application distributed by MyPHPSoft. It is available for Unix, Linux, and Microsoft Windows operating systems.

It has been reported that a problem with the checking of input by MyPHPLinks exists. A problem in the checking of the idsession variable used by MyPHPLinks to verify Administrator access may allow a remote user to gain access to the host. This problem could allow an attacker to gain administrator access to the MyPHPLinks section of a web site.

http://www.example.com/admin/index.php?idsession='%20OR%20''='