Artak Solutions XSS/SQL Vulnerabilities

2013.01.21
Credit: Beni_Vanda
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79
CWE-89

######### # # Exploit Title : Artak Solutions XSS/SQL Vulnerabilities # # Author : IrIsT.Ir # # Discovered By : Beni_Vanda # # Home : http://IrIsT.Ir/forum # # Software Link : http://www.artak.com.mx/ # # Security Risk : High # # Version : All Version # # Tested on : GNU/Linux Ubuntu - win7 , BT # # Dork : intext:"Powered by Artak Solution" # ######### # # Xss Expl0iTs : # # http://target/propiedad-detalle.php?tipo=...[Xss] # # # Xss D3mo : # # http://www.remXax.com.mx/propiedad-detalle.php?tipo=casas&id=20491[xss] # http://www.sireXXmax.com.mx/remaxsunseteagle/propiedad-detalle.php?tipo=casas_condominio&id=552[xss] # # # Sql Expl0iTs : # # http://target/propiedad-detalle.php?tipo=...[sql] # # # Sql D3mo : # # http://www.remaXx.com.mx/propiedad-detalle.php?tipo=casas&id=20491[sql] # http://www.siXremax.com.mx/remaxsunseteagle/propiedad-detalle.php?tipo=casas_condominio&id=552[sql] # ######### # # # Greats : Am!r - C0dex - B3HZ4D - TaK.FaNaR - Dead.Zone - BestC0d3r - esikley # # m3hdi - F@rid - Dr.Tofan - Dj.TiniVini - Nimaark - Spy Developer - one hacker alone # # && All Members In Www.IrIsT.Ir/forum # #########

References:

http://www.artak.com.mx/


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top