hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

qcred11
QUOTE


A vulnerability was reported in Baal Smart Form. A remote user can gain administrative access to the application.

It is reported that a remote user can exploit a flaw in the 'Admin Change Password' page to change the administrative password and then login with that password to gain administrative access.

A demonstration exploit URL is provided:

http://[target]/baalsmartform/regadmin.php

Impact:  A remote user can change the administrative password to an arbitrary value and then login using the new password.

Kynroxes
w00w00 nice human flaw !!
the malicious .php in order to reg the admin lol ...
ths qcred11 for all ...
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.