# Exploit Title: piwigo 2.6.1 - CSRF # Date: 26/02/2014 # Exploit Author: killall-9@mail.com # Vendor Homepage: http://it.piwigo.org/ # Software Link: http://it.piwigo.org/basics/downloads # Version: 2.6.1 # Tested on: Virtualbox debian A CSRF problem is present in the administration panel. Here it is a POF according to a derived POST: Piwigo 2.6.1
So you can add a new arbitrary user. cheerz°°°°