-=[ CSRF PoC 1 - Change Admin Password ]=- GetSimple CMS 2.01 Multiple Vulnerabilities (XSS/CSRF) - Change Admin Password
-=[ CSRF PoC 2 - Delete Page ]=- Do you see this? -=[ CSRF PoC 3 - Delete All Backups ]=- Do you see this? -=[ CSRF PoC 4 - Logout The Administrator ]=- Do you see this? -=[ XSS PoCs ]=- http://[domain]/admin/support.php?success= http://[domain]/admin/archive.php?upd=del-success&id= http://[domain]/admin/upload.php?upd=del-success&id= http://[domain]/admin/pages.php?error= http://[domain]/admin/pages.php?upd=edit-success&id=&type=delete http://[domain]/admin/pages.php?upd=edit-err&type= -=[ Note ]=- More vulnerabilities exist in this version please see the following links: http://secunia.com/advisories/39464 http://secunia.com/advisories/39720