header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Campsite CMS 3.4.0 Multiple CSRF Vulnerabilities – Create Admin User

This PoC demonstrates a CSRF vulnerability in Campsite CMS 3.4.0, which allows an attacker to create an admin user with the credentials 'root' and 'rootroot'. This is done by crafting a malicious HTML page that contains a form with the necessary parameters to create an admin user, and submitting it automatically when the page is loaded.

GetSimple CMS 2.01 Multiple Vulnerabilities (XSS/CSRF)

GetSimple CMS 2.01 is vulnerable to Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS). An attacker can exploit these vulnerabilities to change the admin password, delete pages, delete all backups, and logout the administrator. Additionally, more vulnerabilities can be found in the admin panel.

TheHostingTool 1.2.2 Multiple CSRF Vulnerabilities

TheHostingTool 1.2.2 is vulnerable to multiple CSRF attacks. An attacker can create a malicious HTML page that, when visited by an authenticated user, can perform actions on behalf of the user. The malicious HTML page can be used to create a staff account, delete a staff account, mass email the clients, and logout the administrator.

Joomla Health & Fitness Stats Persistent XSS Vulnerability

This vulnerability exists in the comments section. Goto any of the option like HEALTH STATS,FITNESS STATS or CUSTOM STATS, select Add/Update option and insert your xss script. Once inserted goto Edit records and check your xss.

Frog CMS 0.9.5 Multiple CSRF Vulnerabilities

Frog CMS 0.9.5 is vulnerable to multiple CSRF attacks. An attacker can exploit this vulnerability to create an admin user, delete users, delete pages, delete snippets, delete layouts, and delete files (if the File Manager plugin is installed). The attacker can craft a malicious HTML page containing a form with hidden fields that will be automatically submitted when the page is loaded. The form will contain the parameters necessary to perform the desired action.

Recent Exploits: