Headline
Ekushey Project Manager CRM 3.1 Insecure Settings
Ekushey Project Manager CRM version 3.1 appears to leave default credentials installed after installation.
====================================================================================================================================| # Title : Ekushey Project Manager CRM V3.1 Insecure Settings Vulnerability || # Author : indoushka || # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 66.0.2(32-bit) | | # Vendor : http://creativeitem.com/ | | # Dork : "Login | Ekushey Project Manager CRM" |====================================================================================================================================poc :[+] Dorking İn Google Or Other Search Enggine.[+] leave a default administrative account in place post installation.[+] User = [email protected] & pass : 1234[+] http://127.0.0.1/Ekushey/index.php?admin/dashboardGreetings to :=========================================================================================================================jericho * Larry W. Cashdollar * brutelogic* shadow_00715 *9aylas*djroot.dz*LiquidWorm*Hussin-X*D4NB4R *ViRuS_Ra3cH *yasMouh* CraCkEr |=======================================================================================================================================