# Exploit Title: Ocomon 2.0: Acess administrative Bypass / Multiple Sql Injection # Google Dork: inurl:ocomon/index.php or intitle:Ocomon 2.0-RC6 # Date: 2016.08.18 # Exploit Author: Jonatas Fil a.k.a pwx # Vendor Homepage: ninj4c0d3r.github.io # Version: Latest 2.0RC6 # Tested on: Linux And Windows # CVE : CVE-2005-4664 \xDetails: ======================================== [Software] - Ocomon [Bug Summary] - Multiple SQL Injection (SQLi) [Impact] - High [Affected Version] - Latest 2.0RC6 - Prior versions may also be affected ========================================= \x01- Search by dork in google Dorks: inurl:ocomon/index.php or intitle:Ocomon 2.0-RC6 \x02 - After, To find the victim, open the inspect element in admin page. \x03 - Look for the parameter:
: