vendor:
Pet Grooming Management System
by:
t0pP8uZz
7.5
CVSS
HIGH
Arbitrary Add-Admin Exploit
264
CWE
Product Name: Pet Grooming Management System
Affected Version From: 2
Affected Version To: 2
Patch Exists: Yes
Related CWE: N/A
CPE: a:petgroom:pet_grooming_management_system
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Pet Grooming Management System <= 2.0 Arbitrary Add-Admin Exploit
This exploit allows an attacker to add an admin user to the Pet Grooming Management System (PGMS) version 2.0. The attacker must provide a URL, username, and password to the script, which will then send a POST request to the useradded.php page with the provided credentials. If the request is successful, the attacker will be able to log in to the PGMS with the provided credentials.
Mitigation:
Upgrade to the latest version of PGMS, or apply the patch provided by the vendor.