Any attacker can escalate his privilege to admin using this vulnerability. To exploit this vulnerability, an attacker needs to navigate to the router's login page which is usually the IPV4 default gateway IP, i.e. 172.20.174.1. Then, the attacker needs to append password.cgi to the URL i.e. http://172.20.174.1/password.cgi. Right-clicking and viewing the source code will disclose the username, password and user role of the admin in the comment section. The attacker can then successfully log in using the disclosed credentials.
The security obligation allows an attacker to arbitrary download files.
The vulnerability allows an attacker to inject sql commands into the vulnerable parameters of the Joomla! Component Quiz Deluxe 3.7.4. Proof of Concept examples are provided in the text.
Brickom Cameras allow a low-privilege user to disclose every configuration in the NVRAM, including credentials in clear text, remotely by making a simple requests. This vulnerability, coupled with the fact that there are two default users with known passwords which are rarely modified, allows an attacker to disclose the admin password and latter every config. The most Critical API call is users.cgi?action=getUsers, which provides every user credential. Many other API calls to get information for the WIFI password or FTP credentials, even the whole configuration, are affected depending on the camera model. On the hardware side, the UART console of some models (example: WCB-040Af, with baudrate 38400) is exposed in the PCB and after soldering the corresponding pins and connecting, the resulting shell has root access. A simple NVSHOW command will list every config available in clear text, including credentials.
This module exploits an unauthenticated remote command injection vulnerability in QNAP NAS devices. The transcoding server listens on port 9251 by default and is vulnerable to command injection using the 'rmfile' command. This module was tested successfully on a QNAP TS-431 with firmware version 4.3.3.0262 (20170727).
The vulnerability allows an attacker to inject sql commands. Proof of Concept: http://localhost/[PATH]/[SQL].html -1'+uNiOn+SeleCt++0x31,0x32,0x33,0x34,0x35,(Select+export_set(5,@:=0,(select+count(*)from(information_schema.columns)where@:=export_set(5,export_set(5,@,table_name,0x3c6c693e,2),column_name,0xa3a,2)),@,2)),0x37+--+--+-.html http://localhost/[PATH]/videobattle.html?vote=[SQL] http://localhost/[PATH]/videobattle.html?draw=[SQL]
An attacker is able to inject malicious SQL query to bypass the login page and login as admin.
An attacker is able to inject malicious SQL query to bypass the login page and login as admin of the particular school. The attacker must set the username and password to 'admin' or 1=1 -- - and choose the check box as current and existing user.
After Successfully Connected to D-Link DIR-600 Router(FirmWare Version : 2.01), Any User Can Easily Bypass The Router's Admin Panel Just by adding a simple payload into URL. D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?REQUIRE_FILE= absolute path traversal attack, as demonstrated by discovering the admin password.
The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.