Tool: IntelliTamper
i found the http://www.uny.ac.id/akademik/refleksi/login.php can be exploited with sql injection. Enter the "' or 'a'='a" (without double quote) to the username and password input box, and voila. You can upload there a php shell, too :D
0 comments:
Post a Comment