Exploitation Summary
EIP tracks 1 public exploit for CVE-2012-5005. PoCs published by Cyber-Crystal.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in VR GPub 4.0, allowing an attacker to add an admin account by tricking a logged-in admin into submitting a malicious form. The PoC includes a pre-filled HTML form that submits credentials to the target application.
Description
Cross-site request forgery (CSRF) vulnerability in admin/admin_options.php in VR GPub 4.0 allows remote attackers to hijack the authentication of admins for requests that add admin accounts via an add action.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in VR GPub 4.0, allowing an attacker to add an admin account by tricking a logged-in admin into submitting a malicious form. The PoC includes a pre-filled HTML form that submits credentials to the target application.