CVE-2012-5326
iSupport 1.x - Cross-Site Request Forgery via Administrator Account Addition
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-5326. PoCs published by Or4nG.M4N.
AI-analyzed exploit summary This exploit leverages an HTML injection vulnerability in iSupport v1.x to add an admin user by crafting a malicious form that submits to the admin function. It generates an HTML file and an iframe to trigger the payload.
Description
Cross-site request forgery (CSRF) vulnerability in admin/function.php in IDevSpot iSupport 1.x allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via an administrators action.
Exploits (1)
This exploit leverages an HTML injection vulnerability in iSupport v1.x to add an admin user by crafting a malicious form that submits to the admin function. It generates an HTML file and an iframe to trigger the payload.