Sinisterly
Site exploitable to XSS (adobe cold fusion) - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking)
+--- Thread: Site exploitable to XSS (adobe cold fusion) (/Thread-Site-exploitable-to-XSS-adobe-cold-fusion)



Site exploitable to XSS (adobe cold fusion) - Cake - 03-26-2014

So some kid linked me his schools DB for all of the students etc. They use Adobe Coldfusion, but they also use a version of it that was found to have XSS written all over it.
enjoy,
http://www.mvaims.org/CFIDE/administrator/enter.cfm


RE: Site exploitable to XSS (adobe cold fusion) - BreShiE - 03-26-2014

I'd highly recommend taking a look at this thread.

https://sinister.li/Thread-Tutorial-ColdFusion-Exploit-Hack-Big-Sites-With-Ease-High-Detail


RE: Site exploitable to XSS (adobe cold fusion) - Bannedshee - 03-26-2014

I thought the CF exploit was LFI o.O


RE: Site exploitable to XSS (adobe cold fusion) - BreShiE - 03-26-2014

(03-26-2014, 04:31 PM)Bannedshee Wrote: I thought the CF exploit was LFI o.O

Well technically it's a mixture of the two. But I posted this to show the OP that there's more to do than XSS.


RE: Site exploitable to XSS (adobe cold fusion) - Cake - 03-26-2014

(03-26-2014, 05:16 PM)BreShiE Wrote: Well technically it's a mixture of the two. But I posted this to show the OP that there's more to do than XSS.
I read that thread but this part "value will be displayed on the password." made absolutely no sense.


RE: Site exploitable to XSS (adobe cold fusion) - BreShiE - 03-26-2014

(03-26-2014, 05:22 PM)Kodo Wrote: I read that thread but this part "value will be displayed on the password." made absolutely no sense.

Well try it out and see for yourself. Derp.


RE: Site exploitable to XSS (adobe cold fusion) - Cake - 03-26-2014

(03-26-2014, 05:25 PM)BreShiE Wrote: Well try it out and see for yourself. Derp.
There's no value located anywhere m8.

Site may not be vulnerable >.>
But when I checked like idk 2 months ago it was.