From a9d446b65b5795ff45dd74216a9244dfd5b006f0 Mon Sep 17 00:00:00 2001 From: Offensive Security Date: Sun, 14 Feb 2016 05:02:40 +0000 Subject: [PATCH] DB: 2016-02-14 1 new exploits --- files.csv | 1 + platforms/php/webapps/39384.txt | 42 +++++++++++++++++++++++++++++++++ 2 files changed, 43 insertions(+) create mode 100755 platforms/php/webapps/39384.txt diff --git a/files.csv b/files.csv index 331d6c207..c4c823ec0 100755 --- a/files.csv +++ b/files.csv @@ -35627,6 +35627,7 @@ id,file,description,date,author,platform,type,port 39381,platforms/osx/dos/39381.c,"OS X - IOHDIXControllerUserClient::convertClientBuffer Integer Overflow",2016-01-28,"Google Security Research",osx,dos,0 39382,platforms/multiple/webapps/39382.txt,"SAP HANA 1.00.095 - hdbindexserver Memory Corruption",2016-01-28,ERPScan,multiple,webapps,0 39383,platforms/lin_x86-64/shellcode/39383.c,"x86_64 Linux shell_reverse_tcp with Password - Polymorphic Version",2016-01-29,"Sathish kumar",lin_x86-64,shellcode,0 +39384,platforms/php/webapps/39384.txt,"WordPress Simple Add Pages or Posts Plugin 1.6 - CSRF Vulnerability",2016-01-29,ALIREZA_PROMIS,php,webapps,0 39385,platforms/php/webapps/39385.txt,"ProjectSend r582 - Multiple Vulnerabilities",2016-01-29,"Filippo Cavallarin",php,webapps,80 39387,platforms/php/webapps/39387.py,"iScripts EasyCreate 3.0 - Remote Code Execution Exploit",2016-02-01,"Bikramaditya Guha",php,webapps,80 39388,platforms/lin_x86-64/shellcode/39388.c,"x86_64 Linux shell_reverse_tcp with Password - Polymorphic Version v2",2016-02-01,"Sathish kumar",lin_x86-64,shellcode,0 diff --git a/platforms/php/webapps/39384.txt b/platforms/php/webapps/39384.txt new file mode 100755 index 000000000..ee7d3eebf --- /dev/null +++ b/platforms/php/webapps/39384.txt @@ -0,0 +1,42 @@ +######################################################################## +# Exploit Title: Wordpress simple add pages or posts CSRF Vulnerability +# Date: 2016/29/01 +# Exploit Author: ALIREZA_PROMIS +# Vendor Homepage: https://wordpress.org/plugins/simple-add-pages-or-posts/ +# Software Link: https://downloads.wordpress.org/plugin/simple-add-pages-or-posts.1.6.zip +# Version: 1.6 +# Tested on: ubuntu / FireFox +######################################################################## + +[Exploitation] +https://www.owasp.org/index.php/Cross-Site_Request_Forgery_%28CSRF%29 + +[HTML CODE ] +
+ + + + + +