exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Paliz Portal Cross Site Scripting / SQL Injection

Paliz Portal Cross Site Scripting / SQL Injection
Posted Jul 4, 2011
Authored by Net.Edit0r

Paliz Portal suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
SHA-256 | 75d081437c0be2cc14e27d6d5beea3f9daae0da16722aae5de9bfd4f8126b440

Paliz Portal Cross Site Scripting / SQL Injection

Change Mirror Download
# Exploit Title: Paliz Portal [Sql-XSS] Multiple Vulnerabilities
# Date: 2011.07.02
# Author: Net.Edit0r
# Version : All versian
# Tested on: Windows server 2003
# CVE : -

-----------------------------------------------------------------------------------------
Paliz Portal [Sql-XSS] Multiple Vulnerabilities
-----------------------------------------------------------------------------------------

Author : Net.Edit0r
# Date: 2011.07.02
Location : Iran
Web : http://Black-Hg.Org & http://mn-team.net/
Critical Lvl : Medium
Where : From Remote
My Group : Black Hat Group #BHG
---------------------------------------------------------------------------


Vulnerability:
~~~~~~~~~~~~


./ >>> Page.aspx?search=1[XSS Code]&mID=1641&Page=search/advancedsearch [XSS]
./ >>> News/shownews/[page].aspx?NewsId=[Sqli] 1:[Sql Access ]
./ >>> Default.aspx?tabid=[Sqli] 2:[Sql Access ]

PoC/Exploit:
~~~~~~~~~~

~ [PoC] ~: Http://target.com/Page.aspx?search=1[XSS
Code]&mID=1641&Page=search/advancedsearch

~ [PoC] ~: Http://target.com/News/shownews/[page].aspx?NewsId=[Sqli]

~ [PoC] ~: Http://target.com/[Path]/Default.aspx?tabid=[Sqli]

Dork:
~~~~~
Google : intext:"Paliz Portal"


Timeline:
~~~~~~~~~
- 11 - 05 - 2011 bug found.
- 29 - 06 - 2011 vendor contacted, but no response.
- 2 - 07 - 2011 Advisories release.

Contact:
~~~~~~~~~
Net.Edit0r@att.net ~ Black.hat.tm@gmail.com

---------------------------------------------------------------------------
Greetz To :DarkCoder | 3H34N | Amir-MaGiC | H3x | D3adlY and all bhg member

Spical Th4nks: B3hz4d | Cru3l.b0y | M4Hd1 | HUrr!c4nE | Mikili And All
My Friendz

Web Greetz :http://Black-Hg.Org & http://mn-team.net/ & http://pentesters.ir/

[!] Persian Gulf 4 Ever
[!] I Love Iran And All Iranian People
-------------------------------- [ EOF ] ----------------------------------
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    0 Files
  • 8
    Aug 8th
    0 Files
  • 9
    Aug 9th
    0 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close