==================================================================================================================================== | # Title : WebCalendar v1.3 CSRF Vulnerability | | # Author : indoushka | | # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 69.0(32-bit) | | # Vendor : https://github.com/craigk5n/webcalendar/archive/master.zip | | # Dork : WebCalendar v1.3 | ==================================================================================================================================== poc : [+] Dorking İn Google Or Other Search Enggine. [+] The following html code create a new admin . [+] Go to the line 173. [+] Set the target site link Save changes and apply . [+] infected file : install/index.php. [+] http://127.0.0.1/q7.3/admin/settings.php. [+] save code as poc.html . [+] WebCalendar Setup Wizard
WebCalendar Installation Wizard Step 4
This is the final step in setting up your WebCalendar Installation.
Application Settings
  • HTTP-based authentication was not detected. You will need to reconfigure your web server if you wish to select 'Web Server' from the 'User Authentication' choices below.
Create Default Admin Account: (Admin Account Not Found)
Application Name:
Server URL:
User Authentication:
   Single-User Login:
Read-Only: Yes     No
Environment:
Greetings to :================================================================= jericho * Larry W. Cashdollar * shadow_00715 * LiquidWorm * Hussin-X * D4NB4R | ===============================================================================