搜索 “XSS”

不再关注网络安全

inurl:cartwiz/store/index.asp

  • 2005-09-25
  • shdb
  • 2433 阅读

The CartWIZ eCommerce Shopping Cart System will help you build your online store through an interactive web-based e-commerce administration interface.There are, multiple sql injection and xss in cartwiz asp cart.http://neworder.box.sk/explread.php...

intitle:"Control panel" "Control Panel Login" ArticleLive inurl:admin -demo

  • 2005-09-25
  • shdb
  • 1405 阅读

Build, manage and customize your own search engine friendly news / article site from scratch -- with absolutely no technical experience.Authentication bypass, sql injections and xss in ArticleLive 2005http://neworder.box.sk/explread.php?newsid=13582

"powered by ITWorking"

  • 2005-08-21
  • shdb
  • 1748 阅读

saveWebPortal 3.4 remote code execution / admin check bypass / remote fileinclusion / cross site scripting author site: http://www.circeos.itdownload page: http://www.circeos.it/frontend/index.php?page=downloadsa) remote code execution:a user can ...

"Powered by FunkBoard"

  • 2005-08-08
  • shdb
  • 2270 阅读

FunkBoard V0.66CF (possibly prior versions) cross site scripting, possible database username/password disclosure & board takeover, possible remote code execution software: author site: http://www.[path_to_funkboard].co.uk/ xss: http://[target]...

PHPFreeNews inurl:Admin.php

  • 2005-08-07
  • shdb
  • 2213 阅读

29/07/2005 8.36.03PHPFreeNews Version 1.32 (& previous) sql injection/login bypass, cross site scripting, path disclosure, information disclosure author site: http://www.phpfreenews.co.uk/Main_Intro.phpxss poc:http://[target]/[path]/inc/Footer...

inurl:nquser.php filetype:php

  • 2005-08-07
  • shdb
  • 1572 阅读

Netquery 3.1 remote commands execution, cross site scripting, information disclosure poc exploit software: author site: http://www.virtech.org/tools/ a user can execute command on target system by PING panel, if enabled like often happens, using p...

"Powered by FlexPHPNews" inurl:news | inurl:press

  • 2005-08-07
  • shdb
  • 2013 阅读

24/07/2005 2.38.13Flex PHPNews 0.0.4 login bypass/ sql injection, cross site scripting & resource consumption poc exploitsoftware:author site:http://www.china-on-site.com/flexphpnews/downloads.phpxss / cookie disclosure:http://[target]/[path]/...

intext:"Powered By: Snitz Forums 2000 Version 3.4.00..03"

  • 2005-06-21
  • shdb
  • 1629 阅读

snitz Forum 2000 v 3.4.03 and older is vulnerable to many things including XSS. See http://www.gulftech.org/?node=research&article_id=00012-06162003. This is a sketchy search, finding vulnerable versions 3.4.00-3.4.03. Older versions are vulne...

inurl:sphpblog intext:"Powered by Simple PHP Blog 0.4.0"

  • 2005-05-30
  • shdb
  • 6059 阅读

simple PHP Blog is vulnerable to mutiple attacks:Vulnerabilities:~~~~~~~~~~~~~~~~A. Full Path disclosuresB. XSS in search.phpC. Critical Information dislosures http://www.securityfocus.com/archive/1/395994

inurl:citrix/metaframexp/default/login.asp? ClientDetection=On

  • 2005-01-20
  • shdb
  • 6280 阅读

Citrix (http://citrix.com) is a web application that allows remote access via a client for companies, institutions, and government agencies to "published" folders, files, drives, and applications on the server and often the attached netw...