Topic : | Hasta Blog XSS Vulnerability
|
SecurityAlert : 6921
CVE : CVE-2009-4580
CWE : CWE-79
SecurityRisk : Low (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : Yes
Exploit Available : Yes
Credit : LionTurk
Published : 07.01.2010
Affected Software : | hastablog:hasta_blog:2.3 |
 Advisory Content : ###########################################
#==========================================================================
====
_ _ _ _ _ _
/ \ | | | | / \ | | | |
/ _ \ | | | | / _ \ | |_| |
/ ___ \ | |___ | |___ / ___ \ | _ |
/_/ \_\ |_____| |_____| /_/ \_\ |_| |_|
# Script Name : Hasta Blog
#
#
# Bug Type : XSS vulnerability
#
# [»] Founder: [ LionTurk - Bylionturk@kafam1milyon.com
#
# Note:Forever RevengeHack.Com
#
# Download Script : http://download.hastablog.com/hastablogv2.3.zip
#
###########################################
example :
http://[target]/[path]/yorumyaz.php?id=1[XSS-Vuln]
/blog.php?id=1=[XSS-Vuln]
Bizim Elemanlar:
eXceptioN,CodeInside,CorDoN,Hack3ra,Rex aL0ne,By_HKC
Not:Cok B0ktan OLdu Ama �dare Edin
References :
http://xforce.iss.net/xforce/xfdb/55052
http://www.osvdb.org/61349
http://www.exploit-db.com/exploits/10641
http://secunia.com/advisories/37975
http://packetstormsecurity.org/0912-exploits/hastablog-xss.txt
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|