# Software................Front Accounting 2.3.4 # Vulnerability...........Cross-site Request Forgery # Threat Level............Low (1/5) # Download................http://frontaccounting.com/wb3/ # Discovery Date..........4/27/2011 # Tested On...............Windows Vista + XAMPP # ------------------------------------------------------------------------ # Author..................AutoSec Tools # Site....................http://www.autosectools.com/ # Email...................John Leitch # ------------------------------------------------------------------------ # # # --Description-- # # A cross-site request forgery vulnerability in Front Accounting 2.3.4 # can be exploited to create a new admin. # # # --PoC-->