# Exploit Title :----------------- : PizzaInn Restaurant Scripti (Beta v3) - (message-exec.php) - CSRF Send Inbox Message. # Author :------------------------ : Nassim Asrir # Author Company :------------------------ : HenceForth # Author Email :------------------------ : wassline@gmail.com # Google Dork :---------------- : - # Date :-------------------------- : 20/10/2016 # Type :-------------------------- : webapps # Platform : -------------------- : PHP # Software link : -------------- : http://wmscripti.com/php-scriptler/pizzainn-restaurant-scripti-beta-v3.html ############################ CSRF Send Inbox Message Vulnerabilty ############################ ## Exploit ##

Messages Management

SEND A MESSAGE

Subject
Message Box
 

## Proc ## - P.S: You must to register in the site to see the Inbox Message send by Admin. - Create a .html File and Put the Code. - Navigate the File in your Localhost . - and Create Message in The Text Box and you redirect to http://site/script/admin/access-denied.php - and You get the Message "Access Denied! You do not have access to this resource." but don't worry. when you get the Message go to Your account . and you can see [Inbox] Navigate it and you see the Message .

CSRF By Nassim Asrir