vendor:
ReVou Twitter Clone
by:
G4N0K
7.5
CVSS
HIGH
Admin Password Changing Exploit
N/A
CWE
Product Name: ReVou Twitter Clone
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
ReVou Twitter Clone Admin Password Changing Exploit
ReVou Twitter Clone is a commercial script written in PHP and MySQL. It is vulnerable to an admin password changing exploit. An attacker can reset the admin password and then login as admin. The attacker can then use the path http://site.tld/revou/adminlogin/index.php?id=dbimport to upload a php shell script. The uploaded file can be accessed at http://site.tld/revou/db_backup/shell.php.
Mitigation:
Ensure that the admin password is strong and not easily guessable. Use two-factor authentication for admin accounts.