what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Wolf CMS 0.75 Persistent Cross Site Scripting

Wolf CMS 0.75 Persistent Cross Site Scripting
Posted Mar 26, 2012
Authored by Ivano Binetti

Wolf CMS versions 0.75 and below suffer from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | bf5531ebf0d1f42a147d86f362d0405a209a4ad6e8e3ce3b8be40adb10d4cde7

Wolf CMS 0.75 Persistent Cross Site Scripting

Change Mirror Download
+--------------------------------------------------------------------------------------------------------------------------------+
# Exploit Title : Wolfcms <= 0.75 new Persistent XSS
# Date : 26-03-2012
# Author : Ivano Binetti (https://www.ivanobinetti.com)
# Software link : https://wolfcms.googlecode.com/files/wolfcms_075.zip
# Vendor site : https://www.wolfcms.org/
# Version : 0.75 and lower
# Tested on : Debian Squeeze (6.0)
# Original Advisory: https://www.webapp-security.com/2012/03/wolf-cms-new-persistent-xss/
+--------------------------------------------------------------------------------------------------------------------------------+
Summary
1)Introduction
2)Vulnerabilities Description
3)Exploit
+--------------------------------------------------------------------------------------------------------------------------------+
1)Introduction
Wolfcms is a "ligh-weight, fast, simple and powerful" cms.

2)Vulnerabilities Description
Wolfcms 0.75 (and lower) is prone to a persistent XSS vulnerability due to an improper input sanitization of
"setting[admin_email]" parameter, passed to server side logic (path: "wolfcms/admin/setting") via http POST method.
Exploiting this vulnerability an authenticated admin could insert arbitrary code in "Site email" field which will be executed
when another admin clicks on "Administrator" tab.


3)Exploit
Insert the following code in "Site email" field:
email@email.com"><script>alert(document.cookie)</script>
+--------------------------------------------------------------------------------------------------------------------------------+

Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close