========================================================================================== # Title : Free Monthly Websites 2.0 Administrator Remote Password Change # Date : 10/04/2013 # Name : Free Monthly Websites # Affected Version : 2.0 # Vendor : http://www.freemonthlywebsites2.com/ # Category : Web applications # Severity : High # Tested on : Firefox | Google Chrome | Internet Explorer # Dorks : inurl:/index_ebay.php | "Powered by: Resell Rights Fortune" | Powered By: Free Monthly Websites 2.0 # About the software : Free Monthly Websites 2.0 is here and you no longer have to worry about editing complicated HTML code as we have taken care of that for you, and you no longer have to worry about anything to do with website design as we have taken care of that for you too, adding your Google AdSense Publisher code, taken care of, ClickBank! All done for you, here's how it works. (taken from the vendor's page) ========================================================================================== # Author : Yassin Aboukir # Contact : Yaaboukir [At] Gmail [Dot] com # Site : www.y-aboukir.info # Greetz : To All Ethical Hackers! ========================================================================================== # Proof of concept : Vulnerable page : http://target.com/[path]/admin/file_io.php