WESPA PHP Newsletter 3.0 Administrator Password Change

2011-03-31 / 2011-04-01
Credit: alieye
Risk: High
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

##################################################################################### #### "WESPA PHP Newsletter v3.0" Remote Admin Password Change With #### #### install path #### ##################################################################################### # # # Author: alieye # # # # class : remote # # # # E-mail: cseye_ut@yahoo.com # # # # greetz: C.S.Eye Security Team members # # # # We Are: Alieye , Z0d14c , Bully13 , Stanly , Safety & All Iranian Hackers # # # # Site : www.gcmt.vcp.ir , blog : www.cseye.blogfa.com # ##################################################################################### download : http://www.wespadigital.com/scripts/wespanewsletter/wespa_php_newsletter_v3.zip Dork : intitle:"News list Administration panel" or "WESPA PHP Newsletter v3.0" Example : 1. Go to url : target.com/newsletter/admin.php 2. Clean admin.php and Go to target.com/newsletter/install/install1.php 3. Write new password for admin and click next stage 4. finish install 5. Go to url : target.com/newsletter/admin.php 5. Login admin with new password Date : 03/29/2011


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top