The Joomla nBill Lite component suffers from cross site scripting and html injection vulnerabilities.
3606d2ac2ff13bcedaf6d21dda5490b013927a9fc7dfcf91b3f1c0e6828a97b7
[ TITLE ....... ][ nBill Lite - Joomla component HTML Injection / XSS
[ DATE ........ ][ 07.04.2012
[ AUTOHR ...... ][ http://hauntit.blogspot.com
[ SOFT LINK ... ][ http://
[ VERSION ..... ][
[ TESTED ON ... ][ LAMP
[ ----------------------------------------------------------------------- [
[ 1. What is this?
[ 2. What is the type of vulnerability?
[ 3. Where is bug :)
[ 4. More...
[--------------------------------------------[
[ 1. What is this?
This is very nice component for Joomla, You should try it! ;)
[--------------------------------------------[
[ 2. What is the type of vulnerability?
HTML Injection.
[--------------------------------------------[
[ 3. Where is bug :)
http://joomla/administrator/index.php?option=com_nbill&action=income&task=generated-view&message=[url%3d%27%3E%3Ch1%3Etestuj%3Cbr%3Etestuj2%3C%2fh1%3E]test%3Cbr%3E123[%2furl]
*Tested from admin only!*
[--------------------------------------------[
[ 4. More...
- http://www.joomla.org
- http://hauntit.blogspot.com
- http://www.google.com
- http://portswigger.net
[
[--------------------------------------------[
[ All questions about new projects @ mail now :)
]
[ Best regards
[