Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!

Top Posters

Who's Online (0)

Powered by Vanilla. Made with Bootstrap.
[Private] Exploit! Xataface Admin auth bypass vulnerability!
  • Xin
    Posts: 3,251
    =======================================================
    Xataface Admin Auth Bypass Vulnerability
    =======================================================
    #[+] Discovered by : Xinapse
    #[+] Site : firewire-security.com
    #[+] Email : admin@firewire-security.com

    =======================================================
    =======================================================

    #[+] Vulnerability : Admin/database auth bypass vulnerability
    #[+] Software : Xataface - open source GPL, PHP, Mysql database software
    #[+] Vendor : http://xataface.com
    #[+] Usage : http://www.site.com/admin.php?-action=v ... -mode=list
    #[+] Tested on : http://www.journeytherapeut.com/admin.p ... -mode=list
    #[+] Alert : Most of the sites i tried running this software are vulnerable, only a few used .htaccess
    #[+] Dork :"powered by dataface" "powered by xataface"
    #[+] Description : With this i could edit/delete/create records in the database, create new admin accounts and view all the users and passwords.




    #[+] Greetz :firewire-security team, b10h4z4rd, g3org3
    Xin
  • Nice release! I tried testing it but got no luck XD
  • Lol its definitely not private anymore its all over the web
    And Inj3ct0r.com is claiming it as their own
  • Xin
    Posts: 3,251
    What the FUCK, who owns fucking inj3ct0r.com (and its all over the web) as i submitted to packetstorm , milw0rm, exploit-db and security focus
    Xin
  • lol i wouldnt call it "Private" if you submitted it everywhere...just saying :)
  • Xin
    Posts: 3,251
    was private when it was uploaded,
    Xin
  • GameOver
    Posts: 675
    nice share Xinapse! thanks
  • Xin
    Posts: 3,251
    Thanks :P yeah i was pleased with myself
    Xin
  • Nice share I cant wait to try it!