Headline
Inlislite 3.1 Insecure Settings
Inlislite version 3.1 appears to leave default credentials installed after installation.
====================================================================================================================================| # Title : Inlislite V3.1 Insecure Settings Vulnerability || # Author : indoushka || # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 103.0(64-bit) | | # Vendor : https://inlislite.perpusnas.go.id/?read=installerphp | | # Dork : Inlislite V3.1 © 2017 - 2018 |====================================================================================================================================poc :[+] The vulnerability is about leaving the default settings During the installation of the script and using the default username and password[+] Dorking İn Google Or Other Search Enggine.[+] Use Payload : user=inlislite & pass=inlislite= or user=superadmin & pass=superadmin[+] https://127.0.0.1.online/backend/Greetings to :========================================================================================================================= |jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * shadow_00715 * LiquidWorm* moncet | |=======================================================================================================================================