+--------------------------------------------------------------------------------------------------------------------------------+ # Exploit Title : PlumeCMS <= 1.2.4 CSRF Vulnerability # Date : 20-02-2012 # Author : Ivano Binetti (http://ivanobinetti.com) # Software link : http://sourceforge.net/projects/pxsystem/files/latest/download?source=directory # Vendor site : http://pxsystem.sourceforge.net/ # Version : 1.2.4 (latest) and lower # Tested on : Debian Squeeze (6.0) +--------------------------------------------------------------------------------------------------------------------------------+ +------------------------------------------[Insert and publish NEWS by Ivano Binetti]--------------------------------------------------+ Summary 1)Vulnerability Description 2)Exploit +---------------------------------------------------------------------------------------------------------------------------------+ 1)Vulnerability Description PlumeCMS is prone to a CSRF Vulnerability which allows an attacker to insert and publish "News" (as PlumeCMS names his articles) when an authenticated admin browses a web page containing the following html/javascript code. 2)Exploit

CSRF Exploit to add and publish News

+----------------------------------------------------------------------------------------------------------------------------------+