Exploit Py-Membres 3.1 - 'index.php' Unauthorized Access

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
21886
Проверка EDB
  1. Пройдено
Автор
FROG
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2002-1884
Дата публикации
2002-10-02
Код:
source: https://www.securityfocus.com/bid/5849/info

A vulnerability has been reported for Py-Membres 3.1 that allows remote attackers to obtain administrative privileges on vulnerable installations.

Reportedly, Py-Membres does not fully check some URI parameters. Thus it is possible for an attacker to manipulate URI parameters and log into the system as an arbitrary user without the need for passwords. 

http://[target]/index.php?pymembs=admin
 
Источник
www.exploit-db.com

Похожие темы