Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Exploit
From: Admin () irist ir
Date: Tue, 2 Sep 2008 01:18:29 -0600

Dear Securiteam moderator:
I found a bug in BizDirectory that allows to us to occur a Cross-Site Scripting on a Remote machin.
It works tested with the Vulnerable Software 2.04.
An Exploit Released For This Vulnerability.
A Full Description Can be found in the document:

###############################################################################
#                                                                             #
#                Islamic Republic Of Iran Security Team                       #
#                                                                             #
#                           Www.IrIsT.Ir                                      #
#                                                                             #
###############################################################################
#                                                                             #
# BizDirectory <== 2.04 Cross-Site Scripting Vulnerabilities                  #
#                                                                             #
# Download......: http://www.idevspot.com                                     #
#                                                                             #
# Bug Found.....: IrIsT™                                                      #
#                                                                             #
# discovery.....: Am!r                                                        #
#                                                                             #
# contact.......: Admin [at] IrIsT.ir                                         #
#                                                                             #
# Exploit.......: http://[site]/[path]/?page=[XsS]&mode=search                #
#                                                                             #
# Google Search.: "Powered By BizDirectory 2.04" Or Inurl:"BizDirectory2.04"  #
#                                                                             #
# SP TNX........: dr.flaghk                                                     #
#                                                                             #
###############################################################################


  By Date           By Thread  

Current thread:
  • Exploit Admin (Sep 02)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]