[+] Author: TUNISIAN CYBER [+] Exploit Title: Savsoft Quiz Cross-Site Request Forgery (Add Admin) Vulnerability [+] Date: 24-02-2014 [+] Category: WebApp [+] Tested on: KaliLinux/Windows 7 Pro [+] CWE: CWE-352 [+] Vendor: http://savsoftquiz.com/web/buy-now/ [+] Friendly Sites: na3il.com,th3-creative.com 1.OVERVIEW: SuSavsoft Quiz suffers from a Cross-Site Request Forgery (Add Admin) Vulnerability. 2.Version: All 3.Background: Savsoft Quiz is a php based web application to create and manage online quiz, test, exam on your web server or hosting http://savsoftquiz.com/web/buy-now/ 4.Proof Of Concept: