chichen-tech CMS XSS/SQL Vulnerabilities

2013.02.18
Credit: Beni_Vanda
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79
CWE-89

################################################################################ # # Exploit Title : chichen-tech CMS XSS/SQL Vulnerabilities # # Author : IrIsT.Ir # # Discovered By : Beni_Vanda # # Home : http://IrIsT.Ir/forum # # Software Link : http://www.cct95.com/ # # Security Risk : High # # Version : All Version # # Tested on : GNU/Linux Ubuntu/Fedora , win7 , BT # # Dork : intext:"Design by Chichen-Tech" # ################################################################################ # # Xss Expl0iTs : # # http://target/product.php?id=[Xss] # # # Xss D3mo : # # http://www.amXak.com.tw/product.php?id=21[xss] # http://www.maXcmillan.com.tw/product.php?id=22[xss] # http://www.kaXXllex.com.tw/en/product.php?id=17[xss] # http://www.scXhsch.tw/product.php?id=27[xss] # # # Sql Expl0iTs : # # http://target/product.php?id=[sql] # # # Sql D3mo : # # http://www.amXpak.com.tw/product.php?id=21[sql] # http://www.macXmillan.com.tw/product.php?id=22[sql] # http://www.kallex.cXom.tw/en/product.php?id=17[sql] # http://www.schXsch.tw/product.php?id=27[sql] # ################################################################################ # # Gr33tz : Am!r ,C0dex ,B3HZ4D ,TaK.FaNaR ,0x0ptim0us ,MR.F@RDIN # skote_vahshat ,Sukhoi Su-37 ,Net.W0lf , rEd X ,x3o-1337 , No PM && # m3hdi , Sukhoi Su-71 , IR Anonymous , joker_s , Mr.epsilon ,godfather # All Turkish/Iranian/Kurdish/Bangladesh Hackerz # ################################################################################

References:

http://IrIsT.Ir/forum
http://www.cct95.com/


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top