Purle Devloper Panel 1.0 Insecure Direct Object Reference ≈ Packet Storm

Purle Devloper Panel 1.0 Insecure Direct Object Reference ≈ Packet Storm

Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]

Purle Devloper Panel 1.0 Insecure Direct Object Reference[6]
Authored by indoushka[7]

Purle Devloper Panel version 1.0 suffers from an insecure direct object reference vulnerability that allows an unauthenticated user to update passwords.

SHA-256 | 09602b15944fd8f6ca6576813cf5614b52f48c4af7af9eddcbe67850c33c8a7b

Change Mirror[11] Download[12]

        ====================================================================================================================================
| # Title : Purle Devloper Panel ver 1.0 Unauthorized administrative access Vulnerability |
| # Author : indoushka |
| # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 102.0.1(64-bit) |
| # Vendor : http://www.njmweb.we.bs/Purple10/PURPLEV10.zip |
| # Dork : "Purle Devloper Panel" |
====================================================================================================================================
poc :
[+] an unauthenticated access allow you to update password.
[+] Dorking İn Google Or Other Search Enggine.
[+] Use payload : /user_update.php
[+] https://127.0.0.1/purple.iprebrandsapp/user_update.php
Greetings to :=========================================================================================================================
|
jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * shadow_00715 * LiquidWorm* moncet |
|
=======================================================================================================================================

Login[13] or Register[14] to add favorites

File Archive:

June 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa

File Tags

File Archives

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services[119]
Hosting By
Rokasec[120]
close
Image

Pensée du jour :

Ce que l'homme a fait ,

l'homme peut le défaire.

 

"No secure path in the world"