######################################## ####################################
#
# Title: Xingguang media management system kill Vulnerability
# Time: 2011-10-30
# Team: makebugs
# Author: Fate http://t.qq.com/MakeBug http://hi.baidu.com/micropoor
######################################## ####################################
'Although the vulnerability is caused by carelessness, it is sufficient to kill the entire system.
'The code will not be pasted due to international issues.
'The added account in the background has no authentication permission, resulting in Direct Addition of account
Http://www.bkjia.com/manageadmin/System/manage_admin.asp
Http://www.bkjia.com/manageadmin/System/manage_admin_add.asp
Other information:
Http://www.bkjia.com/manageadmin/editor/admin/login. asp
SUsername = "xgnic"
SPassword = "xgnic1281"
I will continue to analyze this system. Because it is interesting. It is clear that the permission is verified, but cross-origin is supported. There are too many codes. We will continue to post code subsidies in the future.
Www.2cto.com repair: Verification