# Exploit Title: Pluck cms multiple vulnerabilit� # Date: 09/01/2012 # Author: Gordon Security # Vendor or Software Link: www.pluck-cms.org # Version: 4.7 # Category: webapps # Website:www.gordon-security.blogspot.com C.S.R.F. #1 #[p.o.c.] Change admin e-mail and change title blog Gordon Security

www.gordon-security.blogspot.com

CSRF Exploit to change Admin E-mail and Blog Title

C.S.R.F. #2 #[p.o.c.] Add page to blog Gordon Security

www.gordon-security.blogspot.com

CSRF Exploit to add page

C.S.R.F #3 #[p.o.c.] Add categorie Gordon Security

www.gordon-security.blogspot.com

CSRF Exploit to add categorie