Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-42671 — CVE-2021-42671 - Broken access control vulnerability in the Engineers online portal system. | Kitploit
Tools/GitHubGitHub/0xdeku/cve-2021-42671
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration TestingMisconfiguration
GitHub0xdeku/cve-2021-42671

CVE-2021-42671

CVE-2021-42671 - Broken access control vulnerability in the Engineers online portal system.

View Repository
14 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-42671

CVE-2021-42671 - Broken access control vulnerability in the Engineers online portal system.

Technical description:

A broken access control vulnerability exists in the Engineers Online Portal. An attacker can leverage this vulnerability in order to bypass access controls and get his hands on all the files uploaded to the web server without the need of authentication or authorization.

Vulnerable domain - http://localhost/nia_munoz_monitoring_system/admin/uploads/

Proof of concept (Poc) -

Navigate to http://localhost/nia_munoz_monitoring_system/admin/uploads/ in order to bypass the access control of the target web server. As a result you can reach sensetive information stored on the web server uploads folder.

CVE-2021-42671

References -

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42671

https://nvd.nist.gov/vuln/detail/CVE-2021-42671

Discovered by -

Alon Leviev(0xDeku), 22 October, 2021.

Download Tool