# Exploit Title: Jax Guestbook 3.50 Admin Login Exploit # Date: December 23rd, 2009 # Author: Sora # Software Link: # Version: 3.50 # Tested on: Windows and Linux ------------------------------------------- Google Dork: "inurl:guestbook.admin.php?

action=settings" We can access the admin directory of Jax Guestbook 3.50 to edit the admin settings.

================================================================================= ========= Volt Edit CMS SQL Injection Admin Login Bypass & Shell Upload Vulnerability ================================================================================= ========= :----------------------------------------------------------------------------------------------------------------------------------------: : # Exploit Title : Volt Edit CMS SQL Injection Admin Login Bypass & Shell Upload Vulnerability : # Date : 18 August 2013 : # Author : X-Cisadane : # CMS Developer : # Version : ALL : # Category : Web Applications : # Vulnerability : SQL Injection Admin Login Bypass & Shell Upload Vulnerability : # Tested On : Version 26.0.1410.64 m (Windows XP SP 3 32-Bit English) : # Greetz to : X-Code, Borneo Crew, Depok Cyber, Explore Crew, Code Nesia, Bogor-H, Jakarta Anonymous Club, Jabar Cyber, Winda Utari :----------------------------------------------------------------------------------------------------------------------------------------: A multiple vulnerabilities has been identified in "Volt Edit CMS", which could be exploited by attackers to bypass security restrictions into admin panel.