[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
EnanoCMS 1.1.8pl1 XSS Vulnerability
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: EnanoCMS 1.1.8pl1 XSS Vulnerability
- From: dennis.veninga@xxxxxxxxx
- Date: Wed, 25 Feb 2015 15:30:13 GMT
# Exploit Title: EnanoCMS 1.1.8pl1 XSS Vulnerability
# Google Dork: "Website engine powered by Enano"
# Date: 24-2-2015
# Exploit Author: Dennis Veninga
# Vendor Homepage: http://enanocms.org
# Version: 1.1.8pl1
# Tested on: Firefox 36 & Chrome 38 / W8.1-x64
XSS Vulnerability in comments:
http://{target}/enanocms/index.php/Main_Page?do=comments