Menu

Search for hundreds of thousands of exploits

"Online Airline Booking System - Multiple Vulnerabilities"

Author

Exploit author

"Manish Tanwar"

Platform

Exploit platform

php

Release date

Exploit published date

2016-01-05

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
Exploit Title : Online Airline Booking System multiple vulnerabilities
Author         : WICS
Date             : 05/1/2016
Software Link  : http://sourceforge.net/projects/oabs/
Affected Version: All
 
 
Overview:
 
 
The Online Airline Booking System is designed to be an all in one solution for an airline wishing to speed up and save money compared to a traditional booking system. It consists simply of a server-side web application combined powerful backend database to provide the user with a highly accessible system
 
 1. Authentication Bypass
 
Vulnerability exist in admin panel authentication mechanism due to use of $_COOKIE['LoggedIn'] , as $_COOKIE variable can be manipulated by user 
so any user can login to admin panel without knowing username password
line no. 2          if(!isset($_COOKIE['LoggedIn'])) die("You are not logged in!");

Just set cookie value LoggedIn=yes in request header and web application will let you login.
like this 
Cookie: LoggedIn=yes

2. Application Reinstallation
 
install.php is the page which can be used for application reinstallation.
open link 
application/install.php

a form will appear, first text field is for new admin username and second field is for new password of web application
proceed with installation and web application will setup with new attacker supplied admin username password
Release Date Title Type Platform Author
2020-12-02 "aSc TimeTables 2021.6.2 - Denial of Service (PoC)" local windows "Ismael Nava"
2020-12-02 "DotCMS 20.11 - Stored Cross-Site Scripting" webapps multiple "Hardik Solanki"
2020-12-02 "NewsLister - Authenticated Persistent Cross-Site Scripting" webapps multiple "Emre Aslan"
2020-12-02 "Mitel mitel-cs018 - Call Data Information Disclosure" remote linux "Andrea Intilangelo"
2020-12-02 "ChurchCRM 4.2.0 - CSV/Formula Injection" webapps multiple "Mufaddal Masalawala"
2020-12-02 "Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit Profile" webapps multiple "Shahrukh Iqbal Mirza"
2020-12-02 "Ksix Zigbee Devices - Playback Protection Bypass (PoC)" remote multiple "Alejandro Vazquez Vazquez"
2020-12-02 "Anuko Time Tracker 1.19.23.5311 - No rate Limit on Password Reset functionality" webapps php "Mufaddal Masalawala"
2020-12-02 "ChurchCRM 4.2.1 - Persistent Cross Site Scripting (XSS)" webapps multiple "Mufaddal Masalawala"
2020-12-02 "IDT PC Audio 1.0.6433.0 - 'STacSV' Unquoted Service Path" local windows "Manuel Alvarez"
Release Date Title Type Platform Author
2018-03-27 "TestLink Open Source Test Management < 1.9.16 - Remote Code Execution (PoC)" remote linux "Manish Tanwar"
2018-03-02 "TestLink Open Source Test Management < 1.9.16 - Remote Code Execution" remote php "Manish Tanwar"
2017-10-22 "WordPress Plugin Polls 1.2.4 - SQL Injection (PoC)" remote php "Manish Tanwar"
2017-07-04 "Joomla! 3.7 - SQL Injection" remote php "Manish Tanwar"
2017-02-03 "Posnic Stock Management System - SQL Injection" remote php "Manish Tanwar"
2017-01-26 "PHPBack < 1.3.1 - SQL Injection / Cross-Site Scripting" webapps php "Manish Tanwar"
2016-01-05 "Online Airline Booking System - Multiple Vulnerabilities" webapps php "Manish Tanwar"
2015-10-26 "Joomla! 3.2.x < 3.4.4 - SQL Injection" webapps php "Manish Tanwar"
2015-08-26 "Magento eCommerce - Remote Code Execution" webapps xml "Manish Tanwar"
2015-08-25 "vBulletin 3.6.0 < 4.2.3 - 'ForumRunner' SQL Injection" webapps php "Manish Tanwar"
2015-06-19 "Lively Cart - SQL Injection" webapps multiple "Manish Tanwar"
2015-04-09 "WordPress Plugin Windows Desktop and iPhone Photo Uploader - Arbitrary File Upload" webapps php "Manish Tanwar"
2015-03-22 "Joomla! Component Spider FAQ - SQL Injection" webapps php "Manish Tanwar"
2015-01-22 "ecommerceMajor - SQL Injection / Authentication Bypass" webapps php "Manish Tanwar"
2014-12-23 "PHPMyRecipes 1.2.2 - 'browse.php?category' SQL Injection" webapps php "Manish Tanwar"
2014-12-08 "PBBoard CMS - Persistent Cross-Site Scripting" webapps php "Manish Tanwar"
2014-05-20 "Clipperz Password Manager - '/backend/PHP/src/setup/rpc.php' Remote Code Execution" webapps php "Manish Tanwar"
import requests
response = requests.get('http://127.0.0.1:8181?format=json')

For full documentation follow the link above

Cipherscan. Find out which SSL ciphersuites are supported by a target.

Identify and fingerprint Web Application Firewall (WAF) products protecting a website.