Add Super User:
Add Post:
# Exploit Title: PiXie CMS v1.04 CSRF to hidden cookie steal Needs to be modified for clean URLS. Place this on your server and replace SITE_AND_PATH with the location of the Pixie CMS. Then point COOKIE_STEALER_SITE at a cookie stealer I've called it log.php and it GETs then logs the data variable. (https://github.com/Spyware/The-Toolkit/blob/master/recon/multi/cookie-stealer/log.php works) along with a writable log file called log. Now include this in a secret (make it small and hidden) iframe in a link and send it to an Admin. How this works, the little iframe first causes the admin to secretly post a new blog article (dated in the year 2000 so it wont be on the front page, maybe even make it non-public). Then redirects him to it. This article steals his cookie. We can do this because of predictable permalinks. All this happens in seconds in a possibly hidden iframe. The only evidence? It will be in his latest actions log and the blog post (which will hopefully be hidden deep in the archives). -->