# Exploit Title :Kloxo-MR 6.5.0 CSRF Vulnerability # Vendor Homepage :https://github.com/mustafaramadhan/kloxo/tree/dev # Version :Kloxo-MR 6.5.0.f-2014020301 # Tested on :Centos 6.4 # Exploit Author :Necmettin COSKUN =>@babayarisi # Blog :http://www.ncoskun.com http://www.grisapka.org # Discovery date :03/12/2014 # CVE :N/A Kloxo-MR is special edition (fork) of Kloxo with many features not existing on Kloxo official release (6.1.12+). This fork named as Kloxo-MR (meaning 'Kloxo fork by Mustafa Ramadhan'). ================ CSRF Vulnerability Vulnerability ================ Kloxo-MR has lots of POST and GET based form applications like Kloxo stable , some inputs escaped from specialchars but inputs dont have any csrf protection or secret key So an remote attacker can manipulate this forms to add/delete mysql user,create/delete subdomains or add/delete ftp accounts. Poc Exploit ================