########################################################################################################################## # Title: WHMCS 5 Multiple CSRF (Add Admin) and XSS Vulnerability # Version: Latest version 5.1 and other previous version maybe vulnerable # Vendor: www.whmcs.com # Date: 2012-05-30 # Tested on: win/linux # Author/Found by: Shadman Tanjim # Email: shadman2600@gmail.com # Greetz: Sayem Islam, Shahee Mirza, JingoBD, ManInDark, Rohit And All Crew and Members of Bangladesh Cyber Army. # Special Thanks: x8631p # Google Dork: "Powered by WHMCompleteSolution" or inurl:WHMCS ############################################################################################################################ CSRF Vulnerability: Get: http://site.com/clientarea.php http://site.com/admin/index.php http://site.com/admin/login.php Post: http://site.com/admin/login.php http://site.com/cart.php http://site.com/admin/configadmins.php http://site.com/pwreset.php p0c: