Liferay 6.1 Default Configuration Compromise
https://packetstormsecurity.com/files/112057/liferay-config.tgz
https://packetstormsecurity.com/files/112057/liferay-config.tgzhttps://packetstormsecurity.com/files/112057/Liferay-6.1-Default-Configuration-Compromise.htmlSat, 21 Apr 2012 00:14:23 GMTBy utilizing the json webservices exposed in Liferay Portal version 6.1 you can register a new user with any role in the system, including the built in administrator role. Proof of concept included.