The document describes SQL injection and authentication bypass vulnerabilities in CommPort 1.01. The SQL injection occurs due to unsanitized user input in the signup.cgi script, while the authentication bypass leverages improperly restricted HTTP methods in .htaccess files.
Classification
Writeup 90%
Attack Type
Sqli | Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target:CommPort 1.01
No auth needed
Prerequisites:Network access to the target application