Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-6585. PoCs published by Michael Brooks.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in TorrentFlux 2.3, allowing an attacker to create an administrative account via a crafted HTML form. The PoC includes auto-submitting JavaScript to trigger the account creation without user interaction.
Description
Cross-site request forgery (CSRF) vulnerability in html/admin.php in TorrentFlux 2.3 allows remote attackers to hijack the authentication of administrators for requests that add new accounts via the addUser action.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in TorrentFlux 2.3, allowing an attacker to create an administrative account via a crafted HTML form. The PoC includes auto-submitting JavaScript to trigger the account creation without user interaction.