============================================================================= # Title : Multi CSRF vulnerability in DirectAdmin (1.34.4) # Date : 20-3-2010 # Version : 1.34.4 # Author : K053 [K053.Dev0te3 _AT_ gmail] # Tested on : Ubuntu # Vendor : http://www.directadmin.com/ # Download : http://www.directadmin.com/demo.html ============================================================================= # info : DirectAdmin is a graphical web-based web hosting control panel designed to make administration of websites easier. ----------------------------------------------------------------------------- >> Here I have listed some poc , maybe you find more ;) ----------------------------------------------------------------------------- # poc 1 : Add Subdomain | ------------------------- Add subdomain
----------------------------------------------------------------------------- # poc 2 : Delete Subdomain | --------------------------- Delete subdomain Note : You msut set proper name stead selectx, for example if test subdomain is at number 2 in list, should set it select1. ----------------------------------------------------------------------------- # poc 3 : Delete Email | --------------------------- Delete Email Note : You msut set proper name stead selectx, for example if test Mail is at number 2 in list, should set it select1. ----------------------------------------------------------------------------- # poc 4 : Change Email Configuration | ----------------------------------- Note : Able to Cahnge quota, password & Name ----------------------------------------------------------------------------- # poc 5 : Set Redirection | ---------------------------- -----------------------------------------------------------------------------