vendor:
social generator script
by:
Fallaga
7,5
CVSS
HIGH
Remote Add Admin Exploit
N/A
CWE
Product Name: social generator script
Affected Version From: 2.2
Affected Version To: 2.2
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2013
social generator Remote Add Admin Exploit
This exploit allows an attacker to add an admin user to the social generator script version 2.2. The attacker can use the Dork 'inurl:my_profile.php?user_id=MTM=' to find vulnerable websites. The attacker can then use the form to add an admin user with the username and password of their choice.
Mitigation:
The website should be updated to the latest version of the social generator script. Additionally, the website should be monitored for any suspicious activity.