[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

DUgallery 3.0 / Remote Admin Bug

Hi Everybody! 

Application : DUgallery 3.0
Risk        : High Risk
Connecting  : Remote Admin

Normally, DUGallery 3.0 Admin Pannel is : 


But We Can Connect Admin Pannel (No UserName and No PassWord) this page ;


We Can Connect (Direct) Admin Pannel On this page and we can include script, index, etc... Everything...

How can close this bug ? 

Very easy, if we add an acces on this page (UserName and Password Control) , we can close this bug...

Credit : SPYMETA


ProWebLine Information Security Technology / ProWebLine Organization