46 lines
No EOL
2.3 KiB
Text
46 lines
No EOL
2.3 KiB
Text
Date : june, 18 2010
|
|
Vendor url :http://www.axxis.gr/
|
|
Critical Level : HIGH
|
|
Author : Sid3^effects aKa HaRi <shell_c99[at]yahoo.com>
|
|
special thanks to : r0073r (inj3ct0r.com),L0rd CruSad3r,MaYur,MA1201,gunslinger_
|
|
greetz to :All ICW members and my friends :) luv y0 guyz
|
|
#######################################################################################################
|
|
Description:
|
|
Super Messenger allows users of your community to send Private Messages to each other similar to the Facebook concept.
|
|
Super Messenger is a powerful PMS, which gives the ability to your users to send HTML messages, embed images, videos, and even flash movies
|
|
|
|
to your messages!
|
|
Yet it is simple and easy-to-use, with an intuitive and user-friendly interface, based on the success-proven concept of Facebook's messaging.
|
|
It is a stand-alone application, but also integrates seamlessly with Community Builder, JomSocial, SuperGroups, SuperEvents, PUArcade,
|
|
|
|
Fireboard, SimGallery, and Kunena.
|
|
Especially Community Builder users will benefit greatly from the thoughtful cb-login module, the CB Super Messenger tab, and the Connections
|
|
|
|
messaging features.
|
|
When viewing a profile, users will be able to send a private message without the need to redirect to a new page!
|
|
SuperGroups users will be able to send private messages straight from the groups to other group members, and will love the additional
|
|
|
|
features and functionality of Super Messenger, which will also display all group messages in the Inbox and Outbox, with the corresponding
|
|
|
|
group name, linking back to the group's page!
|
|
|
|
#######################################################################################################
|
|
com_joomdocs suffers from persistent xss Vulnerability
|
|
|
|
Xploit:Persistent xss Vulnerability
|
|
|
|
Step 1 : As always register as a user :P
|
|
|
|
Step 2 : Goto your profile..you will able to see "What's on your mind PRO module:"
|
|
|
|
INsert your evil XSS script or xss shell ;) and voila
|
|
|
|
DEMO URL :http://[site]/index.php?option=com_content&view=frontpage&setLang=en-GB&Itemid=1
|
|
|
|
">><marquee><h1>XSS3d By Sid3^effects</h1><marquee> is posted in the What's on your mind PRO module :)
|
|
|
|
|
|
|
|
###############################################################################################################
|
|
# 0day no more
|
|
# Sid3^effects |