==================================================================================================================================== | # Title : QUICKAD CMS 7.3 CSRF Vulnerability | | # Author : indoushka | | # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 66.0.3(32-bit) | | # Vendor : https://codecanyon.net/item/quickad-classified-ads-php-script/19960675?s_rank=189 | | # Dork : "Bylancer, All right reserved" | ==================================================================================================================================== poc : [+] Dorking İn Google Or Other Search Enggine. [+] The following html code create a new admin . [+] Go to the line 61. [+] Set the target site link Save changes and apply . [+] infected file : /admin/panel/admin_add.php . [+] http://127.0.0.1/q7.3/admin/panel/admin_add.php . [+] save code as poc.html .
Greetings to :========================================================================================================================= jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * shadow_00715 * LiquidWorm* | =======================================================================================================================================