Security
Headlines
HeadlinesLatestCVEs

Headline

LMS ZAI 6.1 Insecure Settings

LMS ZAI version 6.1 suffers from an ignored default credential vulnerability.

Packet Storm
#sql#xss#csrf#vulnerability#web#ios#mac#windows#apple#google#ubuntu#linux#debian#cisco#java#php#perl#auth#ruby#firefox

LMS ZAI 6.1 Insecure Settings

Posted Jul 23, 2024

Authored by indoushka

LMS ZAI version 6.1 suffers from an ignored default credential vulnerability.

tags | exploit

SHA-256 | ac6f91ffe20c571e57ac0c8a6aef0c5437b2d37e5f53c46ef41059f24100b7db

Download | Favorite | View

LMS ZAI 6.1 Insecure Settings

====================================================================================================================================| # Title     : LMS ZAI v6.1 Insecure Settings Vulnerability                                                                       || # Author    : indoushka                                                                                                          || # Tested on : windows 10 Fr(Pro) / browser : Mozilla firefox 125.0.1 (64 bits)                                                   || # Vendor    : https://codecanyon.net/item/lmszai-learning-management-system/38383087                                             |====================================================================================================================================poc :[+] Dorking İn Google Or Other Search Enggine.[+] Insecure Settings : appears to leave a default administrative account in place post installation.[+] use payload : user =  [email protected] & pass = 123456[+] https://www/127.0.0.1/www.mylmsin/admin/dashboardGreetings to :==================================================jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R |================================================================

File Tags

  • ActiveX (933)
  • Advisory (86,069)
  • Arbitrary (16,824)
  • BBS (2,859)
  • Bypass (1,852)
  • CGI (1,033)
  • Code Execution (7,777)
  • Conference (691)
  • Cracker (844)
  • CSRF (3,380)
  • DoS (24,989)
  • Encryption (2,389)
  • Exploit (53,058)
  • File Inclusion (4,257)
  • File Upload (989)
  • Firewall (822)
  • Info Disclosure (2,876)
  • Intrusion Detection (914)
  • Java (3,141)
  • JavaScript (895)
  • Kernel (7,164)
  • Local (14,773)
  • Magazine (586)
  • Overflow (13,148)
  • Perl (1,435)
  • PHP (5,220)
  • Proof of Concept (2,381)
  • Protocol (3,723)
  • Python (1,629)
  • Remote (31,604)
  • Root (3,625)
  • Rootkit (525)
  • Ruby (631)
  • Scanner (1,657)
  • Security Tool (8,022)
  • Shell (3,270)
  • Shellcode (1,217)
  • Sniffer (902)
  • Spoof (2,271)
  • SQL Injection (16,585)
  • TCP (2,439)
  • Trojan (690)
  • UDP (901)
  • Virus (669)
  • Vulnerability (32,895)
  • Web (9,947)
  • Whitepaper (3,781)
  • x86 (967)
  • XSS (18,236)
  • Other

File Archives

  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • Older

Systems

  • AIX (429)
  • Apple (2,090)
  • BSD (377)
  • CentOS (58)
  • Cisco (1,927)
  • Debian (7,082)
  • Fedora (1,693)
  • FreeBSD (1,246)
  • Gentoo (4,531)
  • HPUX (880)
  • iOS (376)
  • iPhone (108)
  • IRIX (220)
  • Juniper (69)
  • Linux (50,465)
  • Mac OS X (691)
  • Mandriva (3,105)
  • NetBSD (256)
  • OpenBSD (489)
  • RedHat (16,354)
  • Slackware (941)
  • Solaris (1,611)
  • SUSE (1,444)
  • Ubuntu (9,678)
  • UNIX (9,430)
  • UnixWare (187)
  • Windows (6,667)
  • Other

Packet Storm: Latest News

CUPS IPP Attributes LAN Remote Code Execution