TUCoPS :: Web :: Blogs :: bx1938.htm

artmedic_weblog Cross Site Scriptting Vulnerbility
artmedic_weblog Cross Site Scriptting Vulnerbility
artmedic_weblog Cross Site Scriptting Vulnerbility




                 ########################################################################
             #                                                                      #
             #  .:::::artmedic_weblog Cross Site Scriptting Vulnerbility ::::.      #
             ########################################################################

Virangar Security Team

www.virangar.org
www.virangar.net

--------
Discoverd By :virangar security team(hadihadi)

special tnx to:MR.nosrati,black.shadowes,MR.hesy,Zahra

& all virangar members & all hackerz

greetz:to my best friend in the world hadi_aryaie2004
& my lovely friend arash(imm02tal) from emperor team :)
--------------
download http://artmedic-phpscripts.de/index.php?did=artmedic_weblog.zip
-----
vuln code in artmedic_print.php:

line 42: $date = $_GET[date];
.
.
.
line 49: echo "

$date

"; ---- xss: http://site.com/[patch]/artmedic_print.php?date= -----

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH