[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

DMXReady Members Area Manager Persistent XSS Vulnerability

Author
L0rd CrusAd3r
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-13999
Category
web applications
Date add
06-09-2010
Platform
asp
==========================================================
DMXReady Members Area Manager Persistent XSS Vulnerability
==========================================================

1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0     _                   __           __       __                     1
1   /' \            __  /'__`\        /\ \__  /'__`\                   0
0  /\_, \    ___   /\_\/\_\ \ \    ___\ \ ,_\/\ \/\ \  _ ___           1
1  \/_/\ \ /' _ `\ \/\ \/_/_\_<_  /'___\ \ \/\ \ \ \ \/\`'__\          0
0     \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/           1
1      \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\           0
0       \/_/\/_/\/_/\ \_\ \/___/  \/____/ \/__/ \/___/  \/_/           1
1                  \ \____/ >> Exploit database separated by exploit   0
0                   \/___/          type (local, remote, DoS, etc.)    1
1                                                                      1
0  [+] Site            : Inj3ct0r.com                                  0
1  [+] Support e-mail  : submit[at]inj3ct0r.com                        1
0                                                                      0
1                ###########################################           1
0                I'm L0rd CrusAd3r member from Inj3ct0r Team           1
1                ###########################################           0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1
Author: L0rd CrusAd3r aka VSN [crusader_hmg@yahoo.com]
Exploit Title: DMXReady Members Area Manager Persistent XSS
Vendor url:http://www.dmxready.com/
Version:2
Price:295$
Published: 2010-09-06
GThanx to:r0073r (inj3ct0r.com), Sid3^effects, MaYur, MA1201, Sonic Bluehat,
M4n0j,NoCare,SeeMe, gunslinger, Th3 RDX.
Greetz to : Inj3ct0r Exploit DataBase (inj3ct0r.com)
Special Greetz: Topsecure.net,0xr00t.com,Andhrahackers.com
Shoutzz:- To all ICW & Inj3ct0r members.
~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~
Description:
 
DMXReady Members Area Manager allows you to quickly create a whole area of
your website that is 'members only' so you can control who sees your
content!
 
    * Plug in automatically into DMXReady CMS or secure any web page on your
current ASP-enabled website with one line of script
    * Secure newsletter pages, organizational news, photo galleries,
paid-for content, and any online content you like
    * Unlimited security levels
    * Name your own levels i.e. "Visitor", "Member", "Subscriber", etc.
    * Easy-to-use Control Panel means anyone in the office can adjust
security settings
    * Members sign up themselves, which means less administration work for
you
    * Built-in member messaging feature - send to all members or only
certain groups
    * "Lost Password" feature sends password to members automatically
    * Fully open source so you can customize even further
    * Add in your own custom features
 
 
~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~
 
Vulnerability:
 
Persistent XSS :-
 
Step 1) Login into member or User Section
 
Link:
 
http://www.site.com/dmxreadyv2/membersareamanager/membersareamanager.asp?show=login-member
 
Step 2) Go to Edit profile
 
XSS Bug present in following
 
*)Contact Information
 
Address 2
 
*)Shipping Address
 
Address 2
 
*)Profile Details
 
Detail
 
Step 3) Enter your Attack Pattern
 
Step 4) Refresh and View User profile
 
Demo Url:-
http://www.site.com/dmxreadyv2/membersareamanager/membersareamanager.asp?member=&show=member-profile&tab=meta
 
~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~
 
# 0day n0 m0re #
# L0rd CrusAd3r #



#  0day.today [2024-11-15]  #