+--------------------------------------------------------------------------------------------------------------------------------+ # Exploit Title : ForkCMS 3.2.5 Multiple Vulnerabilities # Date : 21-02-2012 # Author : Ivano Binetti (http://ivanobinetti.com) # Software link : http://www.fork-cms.com/download # Vendor site : http://www.fork-cms.com/ # Version : 3.2.5 and lower # Tested on : Debian Squeeze (6.0) +--------------------------------------------------------------------------------------------------------------------------------+ +------------------------------------------[Multiple Vulnerabilities by Ivano Binetti]-------------------------------------------+ Summary 1)Introduction 2)Vulnerabilities Description 2.1 CSRF 2.1.1 Delete Admins or Users 2.1.2 Delete Web Pages 2.1.3 Privilege Escalation 2.2 XSS (Reflected) 3)Personal observations +--------------------------------------------------------------------------------------------------------------------------------+ 1)Introduction ForkCMS is a cms with an "intuitive and user friendly interface". 2)Vulnerabilities Description ForkCMS 3.2.5 (and lower) suffers from CSRF and XSS (reflected) vulnerabilities. 2.1 CSRF ForkCMS 3.2.5 is prone to a CSRF Vulnerability which allows an attacker to delete admins/users, delete web pages and do privilege escalation when an authenticated admin browses a web page containing the following html/javascript code. 2.1.1 Delete Admins or Users