Security
Headlines
HeadlinesLatestCVEs

Headline

Taskhub 3.0.3 Insecure Settings

Taskhub version 3.0.3 suffers from an ignored default credential vulnerability.

Packet Storm
#sql#xss#csrf#vulnerability#web#ios#mac#windows#apple#google#ubuntu#linux#debian#cisco#java#php#perl#auth#ruby#firefox

Taskhub 3.0.3 Insecure Settings

Posted Sep 20, 2024

Authored by indoushka

Taskhub version 3.0.3 suffers from an ignored default credential vulnerability.

tags | exploit

SHA-256 | 7505071b9896db1b7f4f5cd911d9d07b06247bd94dbf46777a4481d4b83f1ddd

Download | Favorite | View

Taskhub 3.0.3 Insecure Settings

=============================================================================================================================================| # Title     : Taskhub v3.0.3 Insecure Settings Vulnerability                                                                              || # Author    : indoushka                                                                                                                   || # Tested on : windows 10 Fr(Pro) / browser : Mozilla firefox 125.0.1 (64 bits)                                                            || # Vendor    : https://codecanyon.net/item/taskhub-project-management-finance-crm-tool/25685874                                            |=============================================================================================================================================poc :[+] Dorking İn Google Or Other Search Enggine.[+] Insecure Settings : appears to leave a default administrative account in place post installation.[+] use payload : user =  [email protected] & pass = 12345678[+] https://www/127.0.0.1/tasks.octalfoxcom/auth/Greetings to :==================================================jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R |================================================================

File Tags

  • ActiveX (933)
  • Advisory (86,862)
  • Arbitrary (17,077)
  • BBS (2,859)
  • Bypass (1,923)
  • CGI (1,047)
  • Code Execution (7,902)
  • Conference (692)
  • Cracker (845)
  • CSRF (3,427)
  • DoS (25,263)
  • Encryption (2,395)
  • Exploit (54,266)
  • File Inclusion (4,274)
  • File Upload (1,017)
  • Firewall (822)
  • Info Disclosure (2,916)
  • Intrusion Detection (918)
  • Java (3,156)
  • JavaScript (908)
  • Kernel (7,281)
  • Local (14,850)
  • Magazine (587)
  • Overflow (13,223)
  • Perl (1,435)
  • PHP (5,271)
  • Proof of Concept (2,411)
  • Protocol (3,749)
  • Python (1,660)
  • Remote (31,888)
  • Root (3,671)
  • Rootkit (529)
  • Ruby (642)
  • Scanner (1,658)
  • Security Tool (8,048)
  • Shell (3,305)
  • Shellcode (1,219)
  • Sniffer (904)
  • Spoof (2,297)
  • SQL Injection (16,725)
  • TCP (2,463)
  • Trojan (690)
  • UDP (919)
  • Virus (675)
  • Vulnerability (33,092)
  • Web (10,138)
  • Whitepaper (3,784)
  • x86 (970)
  • XSS (18,301)
  • Other

File Archives

  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • Older

Systems

  • AIX (430)
  • Apple (2,114)
  • BSD (378)
  • CentOS (61)
  • Cisco (1,954)
  • Debian (7,124)
  • Fedora (1,693)
  • FreeBSD (1,247)
  • Gentoo (4,567)
  • HPUX (881)
  • iOS (389)
  • iPhone (108)
  • IRIX (220)
  • Juniper (71)
  • Linux (51,237)
  • Mac OS X (696)
  • Mandriva (3,105)
  • NetBSD (256)
  • OpenBSD (490)
  • RedHat (16,845)
  • Slackware (941)
  • Solaris (1,615)
  • SUSE (1,444)
  • Ubuntu (9,852)
  • UNIX (9,456)
  • UnixWare (188)
  • Windows (6,772)
  • Other

Packet Storm: Latest News

Ivanti EPM Agent Portal Command Execution