
24 changes to exploits/shellcodes/ghdb ASUS ASMB8 iKVM 1.14.51 - Remote Code Execution (RCE) Ruckus IoT Controller 1.7.1.0 - Undocumented Backdoor Account Dell EMC iDRAC7/iDRAC8 2.52.52.52 - Remote Code Execution (RCE) FLIR AX8 1.46.16 - Remote Command Injection ABB Cylon Aspect 3.08.02 - Cross-Site Request Forgery (CSRF) Ethercreative Logs 3.0.3 - Path Traversal Garage Management System 1.0 (categoriesName) - Stored XSS Nagios Log Server 2024R1.3.1 - Stored XSS ProConf 6.0 - Insecure Direct Object Reference (IDOR) Teedy 1.11 - Account Takeover via Stored Cross-Site Scripting (XSS) WooCommerce Customers Manager 29.4 - Post-Authenticated SQL Injection ABB Cylon Aspect 3.08.03 (webServerDeviceLabelUpdate.php) - File Write DoS ABB Cylon Aspect 4.00.00 (factorySaved.php) - Unauthenticated XSS ABB Cylon Aspect 4.00.00 (factorySetSerialNum.php) - Remote Code Execution Car Rental Project 1.0 - Remote Code Execution KodExplorer 4.52 - Open Redirect NagVis 1.9.33 - Arbitrary File Read phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS) phpMyFAQ 3.2.10 - Unintended File Download Triggered by Embedded Frames Smart Manager 8.27.0 - Post-Authenticated SQL Injection Zabbix 7.0.0 - SQL Injection Hugging Face Transformers MobileViTV2 4.41.1 - Remote Code Execution (RCE) Fortinet FortiOS_ FortiProxy_ and FortiSwitchManager 7.2.0 - Authentication bypass WebMethods Integration Server 10.15.0.0000-0092 - Improper Access on Login Page
24 lines
No EOL
995 B
Text
24 lines
No EOL
995 B
Text
# Exploit Title: ProConf 6.0 - Insecure Direct Object Reference (IDOR)
|
|
# Date: 19/07/2018
|
|
# Exploit Author: S. M. Zia Ur Rashid, SC
|
|
# Author Contact: https://www.linkedin.com/in/ziaurrashid/
|
|
# Vendor Homepage: http://proconf.org & http://myproconf.org
|
|
# Version: <= 6.0
|
|
# Tested on: Windows
|
|
# CVE : CVE-2018-16606
|
|
# Patched Version: 6.1
|
|
|
|
# Description:
|
|
In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows
|
|
any author to view and grab all submitted papers (Title and Abstract) and
|
|
their authors' personal information (Name, Email, Organization, and
|
|
Position) by changing the value of Paper ID (the pid parameter).
|
|
|
|
# PROOF-OF-CONCEPT
|
|
Step 1: Sign In as an author for a conference & submit a paper. Youall get
|
|
a paper ID.
|
|
Step 2: Now go to paper details and change the value of Paper ID (param
|
|
pid=xxxx) to nearest previous value to view others submitted paper &
|
|
authors information.
|
|
http:// <http:>
|
|
[host]/conferences/[conference-name]/author/show_paper_details.php?pid=xxxx |