+-------------------------------------------------------------------------+ # Exploit Title : Socialcms CSRF Vulnerability # Date : 16-02-2012 # Author : Ivano Binetti (http://ivanobinetti.com) # Vendor site : http://socialcms.com # Software link : http://sourceforge.net/projects/socialcms/files/latest/download # Version : 1.0.2 # Tested on : Debian Squeeze (6.0) +-------------------------------------------------------------------------+ +---+[Add Admin Account by Ivano Binetti]---+

I'm adding ADMIN account using CSRF Vulnerability

+----------------+