[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joomla Extension UIajaxIM 1.1 JavaScript Execution Vulnerability

Author
599eme Man
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-5534
Category
web applications
Date add
23-07-2009
Platform
unsorted
================================================================
Joomla Extension UIajaxIM 1.1 JavaScript Execution Vulnerability
================================================================


# [+] Joomla Extension UIajaxIM 1.1 Javascript Execution
# [+] Software : Joomla
# [+] Author : 599eme Man
# [+] Download : http://extensions.joomla.org/extensions/communication/chat/9075/details
#
#[------------------------------------------------------------------------------------]
# 
# [+] Vulnerability
#
#	[+] Javascript Execution
#
#		- Go in : http://www.site.com/ajaxim/, regist you and connect. Join a channel and in the input write : 'r"'><script>alert('xss')</script> (or any javascript after the 'r"'>) and press enter : the javascript is executed.
#		- Click on IM anyone and write in the input : 'r"'><script>alert('xss')</script> (or any javascript after the 'r"'>) and press enter : the javascript is executed
#
#			[+] Demo
#
#				- http://demo.universal-informatique.com/ajaxim/
#
#[------------------------------------------------------------------------------------]
#
#########################################################################################################



#  0day.today [2024-11-16]  #