============================================================================= # Title : Multi CSRF vulnerability in DirectAdmin (1.34.4) # Date : 20-3-2010 # Version : 1.34.4 # Author : K053 [K053.Dev0te3 _AT_ gmail] # Tested on : Ubuntu # Vendor : http://www.directadmin.com/ # Download : http://www.directadmin.com/demo.html ============================================================================= # info : DirectAdmin is a graphical web-based web hosting control panel designed to make administration of websites easier. ----------------------------------------------------------------------------- >> Here I have listed some poc , maybe you find more ;) ----------------------------------------------------------------------------- # poc 1 : Add Subdomain | -------------------------