vendor:
Nwahy Dir
by:
rEcruit
7,5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Nwahy Dir
Affected Version From: Nwahy Articles v1, Nwahy scripts v1, Nwahy book v1
Affected Version To: Nwahy Articles v1, Nwahy scripts v1, Nwahy book v1
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Nwahy Dir v2.1 Change Admin Password Exploit
This exploit allows an attacker to bypass authentication and gain access to the admin panel of Nwahy Dir v2.1. The vulnerability exists in the admincp/admininfo.php file, where the username and password are not properly validated. An attacker can send a POST request to the admininfo.php file with the username and password set to 'admin' to gain access to the admin panel.
Mitigation:
Ensure that authentication credentials are properly validated before allowing access to the admin panel.