vendor:
Advanced Management For Services Sites
by:
alnjm33
7,5
CVSS
HIGH
Remote add admin exploit
264
CWE
Product Name: Advanced Management For Services Sites
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: YES
Related CWE: N/A
CPE: am4ss
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Advneced Management For Services Sites Remote add admin exploit
This exploit allows an attacker to add an admin user to the Advanced Management For Services Sites (AM4SS) software. The attacker can use the Dork 'trace find it' to locate vulnerable sites and then use the provided HTML code to add an admin user with the username 'admin', email 'admin@demo.net', password '123456' and group '1'.
Mitigation:
Ensure that the software is up to date and that all users have strong passwords.