AppServ 2.5.9 Cross Site Scripting

2014-05-29 / 2014-05-30
Credit: sH@rk-Dz
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

AppServ 2.5.9 Cross Site Scripting HOMe : http://www.appservnetwork.com Author : sH@rk-Dz Date: 28/05/2014 Tested on : Linux D0rk : intitle:"AppServ Open Project" -site:www.appservnetwork.com Vulnerable File : /index.php Exploit : http://localhost.com/index.php?appservlang= Demo1:http://testbank.moXe.gov.eg/index.php?appservlang=(xss) Demo2:http://www.fXcea.gov.tw/index.php?appservlang=(xss) In The Name Of Allah ^_^ The Vuln Found in the file ==> index.php index.php at the paramter ?appservlang= we can also inject any code of xss and send by GET in live http-Headers and also we can iject string not only number using Charcode (in hackbar ther's small addon) note:type of the vul is reflected :) Greet's To : All ALG & ARB E-Hackers & Welad cha3b DZ


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top