ଜମା କରନ୍ତୁ #48128: Human Resource Management System v1.0 - Privledge Escalationସୂଚନା

ଶୀର୍ଷକHuman Resource Management System v1.0 - Privledge Escalation
ବର୍ଣ୍ଣନା# Exploit Title: Human Resource Management System v1.0 - Vertical Privilege Escalation # Exploit Author: Krutika Thakur # Vendor Name: oretnom23 # Vendor Homepage: https://www.sourcecodester.com/php/15740/human-resource-management-system-project-php-and-mysql-free-source-code.html # Software Link: https://www.sourcecodester.com/php/15740/human-resource-management-system-project-php-and-mysql-free-source-code.html # Version: v1.0 # Tested on: Parrot GNU/Linux 4.10, Apache Description:- A Vertical Privilege Escalation issue in Human Resource Management System v1.0 allows an attacker to get access into admin account without having any privilege. ` Payload: /employeeadd.php ` Parameter:- http://localhost/hrm/employeeadd.php ` Steps to reproduce:- 1. First login as normal user 2. We have got the above url as: http://localhost/hrm/user/home.php 3. Now lets add one more directory: /employeeadd.php and remove the /user/home.php 4. As we can see now got the admin access and we can make changes in admin panel 5. We can even change the admin password
ଉପଭୋକ୍ତା lucifoxer001 (UID 33693)
ଦାଖଲ10/13/2022 06:05 PM (3 ବର୍ଷ ବର୍ଷ ago)
ମଧ୍ୟମ ଧରଣର10/13/2022 07:26 PM (1 hour later)
ସ୍ଥିତିଗ୍ରହଣ କରାଯାଇଛି
VulDB ଏଣ୍ଟ୍ରି210785 [SourceCodester Human Resource Management System 1.0 Admin Panel employeeadd.php ବିସ୍ତାରିତ ଅଧିକାର]
ପଏଣ୍ଟ17

Want to stay up to date on a daily basis?

Enable the mail alert feature now!