what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

zeroblogXSS.txt

zeroblogXSS.txt
Posted Oct 12, 2005
Authored by trueend5

ZeroBlog versions 1.2a and 1.1f are susceptible to cross site scripting attacks.

tags | exploit, xss
SHA-256 | bea71f694efcc79089a11410c0f538c2188a915129447a7392dd2f94f253781a

zeroblogXSS.txt

Change Mirror Download
Software: ZeroBlog
Vendor: http://www.sothq.net
Version: 1.2a , 1.1f
Bug: XSS
Exploitation: Remote
---------------------------
Introduction:
Zeroblog: Feature ritch weblog, d-board, live webcam
(option, and requires 3th party software), calendar,
poll system, photogallery, smileys, search engine, 80%
customizable and many more... most pages and modules
can be switched on and off, custom text fields and
more!!
---------------------------
vulnerability:
XSS Vulnerability in 'thread.php' that may allow a
remote user to launch cross-site scripting attacks
Using URL decode.
This issue could permit a remote attacker to create a
malicious URI link that includes hostile HTML and
script code. If this link were to be followed, the
hostile code may be rendered in the web browser of the
victim user. This would occur in the security context
of the affected Web site and may allow for theft of
cookie-based authentication credentials or other
attacks.

----------------------------
Demonstration URL:
http://example.com/thread.php?threadID='%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E
-----------------------------
Solution:
There is no vendor-supplied patch for this issue at
this time.
-------------------------------
Credits:
Discovered & released by trueend5
Security Science Researchers Institute Of Iran
[KAPDA.ir]
Original Advisory:
http://irannetjob.com/content/view/141/28/




__________________________________
Yahoo! Music Unlimited
Access over 1 million songs. Try it free.
http://music.yahoo.com/unlimited/
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    0 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close