Kshitish 2.0 Default Credentials

Kshitish Multipurpose eCommerce Platform version 2.0 leaves default administrative credentials installed post installation.


SHA-256 | 2477d52210510658d6214fbccf04faa8b5eec226329f88dd15fa98fd54677c30

====================================================================================================================================
| # Title : kshitish v2.0 Multipurpose eCommerce Platform Insecure Settings Vulnerability |
| # Author : indoushka |
| # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 108.0(64-bit) |
| # Vendor : https://www.yahoobaba.net/ |
| # Dork : "Created by YahooBaba" |
====================================================================================================================================

poc :

[+] The vulnerability is about leaving the default settings
During the installation of the script and using the default username and password

[+] Dorking İn Google Or Other Search Enggine.

[+] Use Payload : user=admin & pass=admin

[+] http://127.0.0.1-stor.com/admin/

Greetings to :=========================================================================================================================
|
jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * shadow_00715 * LiquidWorm* moncet |
|
=======================================================================================================================================

Related Posts