64 lines
No EOL
2.4 KiB
Text
64 lines
No EOL
2.4 KiB
Text
Exploit Title: Esoftpro Online Guestbook Pro Multiple Vulnerability
|
|
Vendor url:http://www.esoftpro.com/
|
|
Version:5.1
|
|
Author: L0rd CrusAd3r aka VSN [crusader_hmg@yahoo.com]
|
|
Published: 2010-07-4
|
|
Greetz to:r0073r (inj3ct0r.com), Sid3^effects, MaYur, MA1201, Sonic Bluehat,
|
|
Sai, KD, M4n0j.
|
|
Special Greetz: Topsecure.net, inj3ct0r Team ,Andhrahackers.com
|
|
Shoutzz:- To all ICW members.
|
|
~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~
|
|
Description:
|
|
|
|
Online Guestbook Pro (formerly known as EGuest PRO) is an award-winning
|
|
comprehensive guestbook system based on the popular guestbook system EGuest.
|
|
New features including Image Verification Code, Admin Interfaces, Theme
|
|
Support, Advanced Search with Highlight, Auto Web/Email Links, IP/Word
|
|
Banning, Blank Line Protection, 250+ Smiley and much more. It excels any
|
|
other guestbook scripts, allowing you to have a truly professional guestbook
|
|
on your website.
|
|
|
|
With Online Guestbook Pro :-
|
|
|
|
1. You will never need to worry about someone messes your website.
|
|
Comprehensive protections including: Image Verification Code, HTML Filter,
|
|
IP Ban, Bad Word Filter, Blank Line Protection, Valid Email Check, Long
|
|
String Conversion, Characters Limit, IP Log etc.
|
|
2. You will be able to have full control over your guestbook. You can
|
|
Search, Sort, Reply, Modify and Remove any entry right in the main
|
|
interface.
|
|
3. You will be able to custom Online Guestbook Pro easily by applying
|
|
different Themes, Language Packs, Header and Footer.
|
|
4. You will be able to interact with and entertain your visitors. Online
|
|
Guestbook Pro supports 250+ Emoticons and Auto Hyperlinks.
|
|
5. You will be notified right after a new entry is submitted.
|
|
|
|
~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~~*~*~*~*~*~*~
|
|
|
|
Vulnerability:
|
|
|
|
*SQL Vulnerability
|
|
|
|
DEMO URL:
|
|
|
|
http://server/OGP/ogp_show.php?display=130&sort=&entry=10&search=[sqli]
|
|
|
|
*XSS Vulnerability
|
|
|
|
DEMO URL :
|
|
|
|
http://server/OGP/ogp_show.php?display=130&sort=&entry=10&search=&search_choice=[xss]
|
|
|
|
*HTML Injection
|
|
|
|
DEMO URL:
|
|
|
|
http://server/OGP/ogp_show.php?display=130&sort=&entry=10&search=&search_choice=[html]
|
|
|
|
# 0day n0 m0re #
|
|
# L0rd CrusAd3r #
|
|
|
|
|
|
--
|
|
With R3gards,
|
|
L0rd CrusAd3r |