gpEasy version 2.3.3 suffers from a cross site scripting vulnerability.
da3b79c98a8be6db367f8948364114f5510972bf88b978ae34186f4c2dca6e7e
[ TITLE ....... ][ gpEasy 2.3.3 - HTML Injection / XSS
[ DATE ........ ][ 29.03.2012
[ AUTOHR ...... ][ http://hauntit.blogspot.com
[ SOFT LINK ... ][ http://gpeasy.com
[ VERSION ..... ][ 2.3.3
[ TESTED ON ... ][ LAMP
[ ----------------------------------------------------------------------- [
[ 1. What is this?
[ 2. What is the type of vulnerability?
[ 3. Where is bug :)
[ 4. More...
[--------------------------------------------[
[ 1. What is this?
This is very nice CMS, You should try it! ;)
[--------------------------------------------[
[ 2. What is the type of vulnerability?
This CMS is vulnerable to Cross-Site Scripting attack because of vulnerable
parameter: jsoncallback. Details presented below.
[--------------------------------------------[
[ 3. Where is bug :)
http://gpEasy_CMS/index.php/Admin_Preferences?gpreq=json&jsoncallback=<h1>test<br>test2<%2fh1>
[--------------------------------------------[
[ 4. More...
- http://hauntit.blogspot.com
- http://www.google.com
- http://portswigger.net
[
[--------------------------------------------[
[ All questions about new projects @ mail now :)
]
[ Best regards
[