Headline
AMSS++ 2.0 Insecure Settings
AMSS++ version 2,0 appears to leave default credentials installed after installation.
====================================================================================================================================| # Title : AMSS++ v 2.0 Insecure Settings Vulnerability || # Author : indoushka || # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 65.0(32-bit) | | # Vendor : http://amssplus.ubn4.go.th/amssplus_download/amssplus_4_31_install.rar | | # Dork : แนะนำให้ใช้บราวเซอร์ Google Chrome "AMSS++" |====================================================================================================================================poc :[+] Dorking İn Google Or Other Search Enggine.[+] Use Login : User = admin & pass = 1234[+] http://127.0.0.1/pmss/index.php====Greetings to :=======================================================================================================================| jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* CraCkEr * djroot.dz * LiquidWorm* Hussin-X *D4NB4R * shadow_00715 * yasMouh |=========================================================================================================================================