Sunday, December 19, 2010

WebEvent Web Calendar by peoplecube.com Non-Persistent XSS

# Exploit Title: WebEvent Web Calendar by peoplecube.com Non-Persistent XSS
# Date: 20 December 2010
# Author: p0pc0rn
# Software Link: http://www.peoplecube.com/
: http://www.peoplecube.com/products-other-web-event.htm



XSS
====
http://site.com/webevent.pl?cmd=[XSS]
http://site.com/webevent.cgi?cmd=[XSS]


Screenshot:



http://img710.imageshack.us/img710/5901/screenshotah.png
http://img694.imageshack.us/img694/5028/screenshotxed.png

Status: Reported.

Thanks

p0pc0rn
Share:

0 comments: