[VIM] WTF: BellaBiblio Admin Login Bypass

Steven M. Christey coley at linus.mitre.org
Tue Jul 31 00:32:37 UTC 2007


I just downloaded the source code and it's as you described.  Looks wrong
to me, too - $admin_name etc. are hard-coded in config.php, which is
included just before this code.  Not to mention that "administrator" isn't
a valid md5 result :)

- Steve


More information about the VIM mailing list