Travel Portal II (6.0) - CSRF Admin Password Change PoC Exploit ~~~~~~~~~~~~~~~[My]~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ [+] Author : KnocKout [~] Contact(onlymail) : knockout@e-mail.com.tr [~] HomePage : http://Cyber-Warrior.Org - http://h4x0resec.blogspot.com - http://www.cyber-warrior.org/100379 [~] Greetz: DaiMon,furty,BackDoor,EthicalHacker,BARCOD3,SZE©,VolqaN,Septemb0x.. Unuttuklarımız affola.. ############################################################ Turkey Security Group 'h4x0re SECURITY' ########################################################### ~~~~~~~~~~~~~~~~[Software info]~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |~Web App. : Travel Portal II (6.0) |~Affected Version : II 6.0 and predecessors.. / all version |~Official Software Web: http://www.tourismscripts.com/scripts/scripts/hotel-cars-flights-villas-flats-custom-potal-script.html |~PRICE : 349 Euro |~RISK : High |~Google Keyword/Dorks : N/A |~Tested On : Kali Linux \ Mozilla Firefox ####################INFO################################ admin password can be changed easily.. ####################Usage Exploit######################## Exploitation Edit to exploit.html target website.. Open exploit.html your browser.. Determine your new password. GO TO ADMIN PANEL.. ####################Example affected sites & Tested on##### http://travelportal.tourismscripts.com/ ( Official Demo ) http://almarjanmakkah.com http://www.istanbulairportal.com ==============================================================================00 Travel Portal II (6.0) - CSRF Admin Password Change PoC Exploit ; exploit.html ==============================================================================0

Travel Portal II (6.0) - CSRF Admin Password Change PoC Exploited by KnocKout

Username:
New Password:
================================================================================= .__ _____ _______ | |__ / | |___ __\ _ \_______ ____ | | \ / | |\ \/ / /_\ \_ __ \_/ __ \ | Y \/ ^ /> <\ \_/ \ | \/\ ___/ |___| /\____ |/__/\_ \\_____ /__| \___ > \/ |__| \/ \/ \/ _____________________________ / _____/\_ _____/\_ ___ \ \_____ \ | __)_ / \ \/ / \ | \\ \____ /_______ //_______ / \______ / \/ \/ \/