Menu

Search for hundreds of thousands of exploits

"Macromedia Dreamweaver MX 6.0 - PHP User Authentication Suite Cross-Site Scripting"

Author

Exploit author

"Lorenzo Hernandez Garcia-Hierro"

Platform

Exploit platform

php

Release date

Exploit published date

2003-08-04

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
source: https://www.securityfocus.com/bid/8339/info

It is possible to create an authentication or access control page, using Dreamweaver MX PHP Authentication Suite. This script will generate an error page that contains dynamic content when a user fails to authenticate correctly to the site.

A cross-site-scripting vulnerability has been reported to affect PHP authentication functions used in PHP access control pages created with the Macromedia Dreamweaver MX PHP Authentication Suite.

An attacker may exploit this condition to execute arbitrary HTML code in the browser of an unsuspecting user.

http://www.example.com/[PATH]/[LOGIN PAGE].php?[ACCESS DENIED VARIABLE]
="><script>alert('.::\/\|NSRG-18-7|/\/::.');</script>
Release Date Title Type Platform Author
2020-12-02 "aSc TimeTables 2021.6.2 - Denial of Service (PoC)" local windows "Ismael Nava"
2020-12-02 "Ksix Zigbee Devices - Playback Protection Bypass (PoC)" remote multiple "Alejandro Vazquez Vazquez"
2020-12-02 "NewsLister - Authenticated Persistent Cross-Site Scripting" webapps multiple "Emre Aslan"
2020-12-02 "Mitel mitel-cs018 - Call Data Information Disclosure" remote linux "Andrea Intilangelo"
2020-12-02 "DotCMS 20.11 - Stored Cross-Site Scripting" webapps multiple "Hardik Solanki"
2020-12-02 "Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit Profile" webapps multiple "Shahrukh Iqbal Mirza"
2020-12-02 "Anuko Time Tracker 1.19.23.5311 - No rate Limit on Password Reset functionality" webapps php "Mufaddal Masalawala"
2020-12-02 "ChurchCRM 4.2.0 - CSV/Formula Injection" webapps multiple "Mufaddal Masalawala"
2020-12-02 "ChurchCRM 4.2.1 - Persistent Cross Site Scripting (XSS)" webapps multiple "Mufaddal Masalawala"
2020-12-02 "IDT PC Audio 1.0.6433.0 - 'STacSV' Unquoted Service Path" local windows "Manuel Alvarez"
Release Date Title Type Platform Author
2003-10-15 "Macromedia ColdFusion MX 6.0 - SQL Error Message Cross-Site Scripting" webapps cfm "Lorenzo Hernandez Garcia-Hierro"
2003-10-03 "Sun Cobalt RaQ 1.1/2.0/3.0/4.0 - 'Message.cgi' Cross-Site Scripting" webapps cgi "Lorenzo Hernandez Garcia-Hierro"
2003-09-29 "Geeklog 1.3.x - Cross-Site Scripting" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-09-29 "Geeklog 1.3.x - SQL Injection" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-08-11 "phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 fatcat Module - 'fatcat_id' Cross-Site Scripting" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-08-11 "phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 earch Module - 'PDA_limit' Cross-Site Scripting" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-08-11 "phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 pagemaster Module - 'PAGE_id' Cross-Site Scripting" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-08-11 "phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 Calendar Module - 'day' Cross-Site Scripting" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-08-11 "PHP Website 0.7.3/0.8.2/0.8.3/0.9.2 Calendar Module - SQL Injection" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-08-08 "PostNuke 0.6/0.7 Downloads Module - TTitle Cross-Site Scripting" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-08-08 "PostNuke 0.6/0.7 web_links Module - TTitle Cross-Site Scripting" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-08-04 "Macromedia Dreamweaver MX 6.0 - PHP User Authentication Suite Cross-Site Scripting" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-06-19 "pMachine 1.0/2.x - Search Module Cross-Site Scripting" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-06-19 "pMachine 1.0/2.x - Multiple Script 'sfx' Full Path Disclosures" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-06-19 "pMachine 1.0/2.x - '/lib/' Multiple Script Direct Request Full Path Disclosures" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-06-13 "Sphera HostingDirector 1.0/2.0/3.0 - VDS Control Panel Account Configuration Modification" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-06-13 "Sphera HostingDirector 1.0/2.0/3.0 VDS Control Panel - Multiple Cross-Site Scripting Vulnerabilities" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-06-09 "H-Sphere 2.x - HTML Template Inclusion Cross-Site Scripting" webapps java "Lorenzo Hernandez Garcia-Hierro"
2003-04-15 "osCommerce 2.2 - 'product_info.php' Denial of Service" dos php "Lorenzo Hernandez Garcia-Hierro"
2003-04-15 "osCommerce 2.2 - Authentication Bypass" webapps php "Lorenzo Hernandez Garcia-Hierro"
import requests
response = requests.get('http://127.0.0.1:8181?format=json')

For full documentation follow the link above

Cipherscan. Find out which SSL ciphersuites are supported by a target.

Identify and fingerprint Web Application Firewall (WAF) products protecting a website.