Written By Michael Brooks Special thanks to str0ke! Product: ManageEngine Firewall Analyzer 5 - XSRF and XSS Vulerable version: Build Version : 5.0.0 Build Number : 5000 Build Date : Apr_25 homepage: http://fwanalyzer.com/ This is live exploit code against the online demo. Go ahead, run it! With this exploit you can execute any SQL query you want, this is not SQL Injection. I think its funny that the sql query is also vulnerable to xss. XSRF to execute Arbatrary SQL Queries. This is not SQL Injection, its better because you can execute *any* query.
Create a new administrative account badmin:badmin: