Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Site exploitable to XSS (adobe cold fusion) filter_list
Author
Message
Site exploitable to XSS (adobe cold fusion) #1
So some kid linked me his schools DB for all of the students etc. They use Adobe Coldfusion, but they also use a version of it that was found to have XSS written all over it.
enjoy,
http://www.mvaims.org/CFIDE/administrator/enter.cfm

Reply

RE: Site exploitable to XSS (adobe cold fusion) #2
I'd highly recommend taking a look at this thread.

https://www.sinister.ly/Thread-Tutorial-...igh-Detail
[Image: F4Z9Dqw.png]

Reply

RE: Site exploitable to XSS (adobe cold fusion) #3
I thought the CF exploit was LFI o.O
Wavy baby

Reply

RE: Site exploitable to XSS (adobe cold fusion) #4
(03-26-2014, 04:31 PM)Bannedshee Wrote: I thought the CF exploit was LFI o.O

Well technically it's a mixture of the two. But I posted this to show the OP that there's more to do than XSS.
[Image: F4Z9Dqw.png]

Reply

RE: Site exploitable to XSS (adobe cold fusion) #5
(03-26-2014, 05:16 PM)BreShiE Wrote: Well technically it's a mixture of the two. But I posted this to show the OP that there's more to do than XSS.
I read that thread but this part "value will be displayed on the password." made absolutely no sense.

Reply

RE: Site exploitable to XSS (adobe cold fusion) #6
(03-26-2014, 05:22 PM)Kodo Wrote: I read that thread but this part "value will be displayed on the password." made absolutely no sense.

Well try it out and see for yourself. Derp.
[Image: F4Z9Dqw.png]

Reply

RE: Site exploitable to XSS (adobe cold fusion) #7
(03-26-2014, 05:25 PM)BreShiE Wrote: Well try it out and see for yourself. Derp.
There's no value located anywhere m8.

Site may not be vulnerable >.>
But when I checked like idk 2 months ago it was.
(This post was last modified: 03-26-2014, 05:52 PM by Cake.)

Reply