TUCoPS :: Web :: Apps :: b06-2073.htm

singapore v0.9.7 XSS Vulnerabilities
singapore v0.9.7 XSS Vulnerabilities
singapore v0.9.7 XSS Vulnerabilities



SOFTWARE: =0D
========= =0D
singapore v0.9.7=0D
=0D
DESCRIPTION: =0D
============ =0D
The system is vulnerable to various XSS attacks=0D
=0D
google dork :  "Powered by singapore v0.9.7" inurl:index.php?gallery=0D
429 results :)=0D
=0D
xss code example=0D
=================0D
www.site.com/images/index.php?gallery=[gallery =0D">name]&image==0D 
=0D
www.site.com/images/index.php?gallery=[gallery name]&image=