exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

interworx-xss.txt

interworx-xss.txt
Posted Aug 28, 2007
Authored by DoZ | Site hackerscenter.com

InterWorx-CP suffers from multiple cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | ec5df45f2a04149b23fb6f238d237640013f38be26c3bdff3ec185d62a33a224

interworx-xss.txt

Change Mirror Download
[HSC] InterWorx-CP Multiple HTMl Injection Vulnerabilities 

The InterWorx Hosting Control Panel (InterWorx-CP) is a dedicated
server control panel. InterWorx suffers from multiple HTMl injection
vulnerabilities. JavaScript and Cross site scripting are just few found
vulns, more sophisticated attacks such as remote file inclusion or even
SQl injection may be possible. An attacker could exploit this vulnerability
to have arbitrary script code execute in the context of the affected site.
This may allow an attacker to steal cookie-based authentication credentials
and to launch other attacks.


Hackers Center Security Group (http://www.hackerscenter.com)
Credit: Doz


Remote: Yes
Local: Yes
Class: Input Validation Error



Products:

- InterWorx-CP Webmaster Level (SiteWorx) v3.0.2
- InterWorx-CP Server Admin Level (NodeWorx) v3.0.2

Vendor: InterWorx L.L.C. http://interworx.com


* Attackers can exploit these issues via a web client.



# Remote Holes:

/nodeworx/index.php/<Evil(XSS)-Code>

/siteworx/index.php/<Evil(XSS)-Code>


# Local Holes:

* (NodeWorx)

/nodeworx/nodeworx.php/<Evil-Code>
/nodeworx/users.php/<Evil-Code>
/nodeworx/lang.php/<Evil-Code>
/nodeworx/themes.php/<Evil-Code>
/nodeworx/setup.php/<Evil-Code>
/nodeworx/siteworx.php/<Evil-Code>
/nodeworx/packages.php/<Evil-Code>
/nodeworx/backup.php/<Evil-Code>
/nodeworx/import.php/<Evil-Code>
/nodeworx/scriptworx.php/<Evil-Code>
/nodeworx/resellers.php/<Evil-Code>
/nodeworx/reseller-packages.php/<Evil-Code>
/nodeworx/http.php/<Evil-Code>
/nodeworx/mail.php/<Evil-Code>
/nodeworx/ftp.php/<Evil-Code>
/nodeworx/mysql.php/<Evil-Code>
/nodeworx/sshd.php/<Evil-Code>
/nodeworx/nfs.php/<Evil-Code>
/nodeworx/cron.php/<Evil-Code>
/nodeworx/ip.php/<Evil-Code>
/nodeworx/firewall.php/<Evil-Code>
/nodeworx/updates.php/<Evil-Code>
/nodeworx/rrd.php/<Evil-Code>
/nodeworx/cluster.php/<Evil-Code>


* (SiteWorx)

/siteworx/siteworx.php/<Evil-Code>
/siteworx/users.php/<Evil-Code>
/siteworx/cron.php
/siteworx/prefs.php
/siteworx/ftp.php/<Evil-Code>
/siteworx/mysql.php/<Evil-Code>
/siteworx/domains.php/<Evil-Code>
/siteworx/htaccess.php/<Evil-Code>
/siteworx/scriptworx.php/<Evil-Code>
/siteworx/stats.php/<Evil-Code>
/siteworx/backup.php/<Evil-Code>
/siteworx/restore.php/<Evil-Code>
/siteworx/httpd.php/<Evil-Code>




Only becoming a Ethical Hacker, you can stop a Hacker. Learn with out having
to pay thousands!- http://kit.hackerscenter.com - The most comprehensive security
pack you will ever find on the net!
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close