exploit the possibilities

DataLife Engine 13.0 Cross Site Scripting

DataLife Engine 13.0 Cross Site Scripting
Posted Aug 1, 2018
Authored by Mostafa Gharzi

DataLife Engine versions 13.0 and below suffer from a cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2018-14777
MD5 | 6f07d9a2f57e9e3154d4c9e3d037f880

DataLife Engine 13.0 Cross Site Scripting

Change Mirror Download
[+] Title: DataLife Engine Core Cross Site Scripting (XSS) & Execution Code
[+] Date: 2018/08/02
[+] Author: Mostafa Gharzi
[+] Team: Maher - CertCC.ir
[+] Vendor Homepage: www.dleviet.com
www.dle-news.com
[+] Tested on: Windows 10 & Kali Linux
[+] Versions: 13.0 and Before
[+] Vulnerable Parameter: Post Method
[+] Vulnerable File: /index.php?do=addnews & /addnews.html
[+} Dork : inurl:/index.php?subaction=userinfo

### Notes:

An attacker can use XSS (in addnews fields section from datalife engine
13.0 and Before)
to send a malicious script to an unsuspecting Admins or users. The end
admins or useras browser
has no way to know that the script should not be trusted, and will execute
the script. Because it thinks the script came from a trusted source, the
malicious script can access any cookies, session tokens, or other sensitive
information retained by the browser and used with that site. These scripts
can even rewrite the content of the HTML page.

### POC:

[+] First, sign up through this path: http://localhost/index.php?do=register
[+] Once logged in, Go to this page: http://localhost/index.php?do=addnews
or
http://localhost/addnews.html
[+] For example, put this code in the fields: <img src="Image link">
"><svg
onload=alert('CertCC')>
"><br>text
[+] When the admin goes to validate your post, he will see your alert or
executable code.
[+] Therefore, the administrator and subsequent users are attacked by XSS.

### Demo PIC:

[+] http://gucert.ir/dle.JPG

### Credit:

[+] CertCC.ir

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

February 2019

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Feb 1st
    22 Files
  • 2
    Feb 2nd
    9 Files
  • 3
    Feb 3rd
    2 Files
  • 4
    Feb 4th
    15 Files
  • 5
    Feb 5th
    50 Files
  • 6
    Feb 6th
    24 Files
  • 7
    Feb 7th
    15 Files
  • 8
    Feb 8th
    6 Files
  • 9
    Feb 9th
    1 Files
  • 10
    Feb 10th
    1 Files
  • 11
    Feb 11th
    22 Files
  • 12
    Feb 12th
    25 Files
  • 13
    Feb 13th
    16 Files
  • 14
    Feb 14th
    32 Files
  • 15
    Feb 15th
    15 Files
  • 16
    Feb 16th
    10 Files
  • 17
    Feb 17th
    2 Files
  • 18
    Feb 18th
    27 Files
  • 19
    Feb 19th
    32 Files
  • 20
    Feb 20th
    0 Files
  • 21
    Feb 21st
    0 Files
  • 22
    Feb 22nd
    0 Files
  • 23
    Feb 23rd
    0 Files
  • 24
    Feb 24th
    0 Files
  • 25
    Feb 25th
    0 Files
  • 26
    Feb 26th
    0 Files
  • 27
    Feb 27th
    0 Files
  • 28
    Feb 28th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2019 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close