Menu

Search for hundreds of thousands of exploits

"FatWire UpdateEngine 6.2 - Multiple Cross-Site Scripting Vulnerabilities"

Author

Exploit author

r0t3d3Vil

Platform

Exploit platform

java

Release date

Exploit published date

2005-12-27

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
source: https://www.securityfocus.com/bid/16073/info

FatWire UpdateEngine is prone to multiple cross-site scripting vulnerabilities.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

These issues affect versions 6.2 and prior. 

http://www.example.com/UpdateEngine?FUELAP_OP=FUELOP_NewScreen&PAGE_ID
=FWS%5FPAGE%5F1399202&FUELAP_SITEDBID=SITE%5F%2D
66&ACTIVITY_ID=FWS%5FWHITEPAPERS%5F1404733&COUNT
RY_ID=INTSITE%5F1167494&CAMPAIGN_ID=SFCAMPAIGN%5
F%2D1&COUNTRYNAME=us&SOURCEPAGE_ID=FWS%5FPAGE%5F1
415379&FUELAP_TEMPLATENAME=[XSS]

http://www.example.com/UpdateEngine?FUELAP_OP=FUELOP_NewScreen&FUELAP_
TEMPLATENAME=fws%5FforgotpasswordForm&SOURCEPAGE_
ID=FWS%5FPAGE%5F1150486&PAGE_ID=FWS%5FPAGE%5F1402
412&EMAIL=[XSS]&CAMPAIGN_ID=SFCAMPAIGN%5F%2D1&COU
NTRY_ID=INTSITE%5F1167494&ERROR=error&ACTIVITY_ID
=FWS%5FWHITEPAPERS%5F1300483&COUNTRYNAME=us&FUELA
P_SITEDBID=SITE%5F%2D66&

http://www.example.com/UpdateEngine?FUELAP_OP=FUELOP_NewScreen&FUELAP_TE
MPLATENAME=fws%5FforgotpasswordForm&SOURCEPAGE_ID=
FWS%5FPAGE%5F1150486&PAGE_ID=FWS%5FPAGE%5F1402412&
EMAIL=&CAMPAIGN_ID=SFCAMPAIGN%5F%2D1&COUNTRY_ID=IN
TSITE%5F1167494&ERROR=error&ACTIVITY_ID=FWS%5FWHIT
EPAPERS%5F1300483&COUNTRYNAME=[XSS]

http://www.example.com/UpdateEngine?FUELAP_OP=FUELOP_NewScreen&FUELAP_TE
MPLATENAME=[XSS]
Release Date Title Type Platform Author
2020-12-02 "Mitel mitel-cs018 - Call Data Information Disclosure" remote linux "Andrea Intilangelo"
2020-12-02 "aSc TimeTables 2021.6.2 - Denial of Service (PoC)" local windows "Ismael Nava"
2020-12-02 "NewsLister - Authenticated Persistent Cross-Site Scripting" webapps multiple "Emre Aslan"
2020-12-02 "Anuko Time Tracker 1.19.23.5311 - No rate Limit on Password Reset functionality" webapps php "Mufaddal Masalawala"
2020-12-02 "Ksix Zigbee Devices - Playback Protection Bypass (PoC)" remote multiple "Alejandro Vazquez Vazquez"
2020-12-02 "DotCMS 20.11 - Stored Cross-Site Scripting" webapps multiple "Hardik Solanki"
2020-12-02 "ChurchCRM 4.2.1 - Persistent Cross Site Scripting (XSS)" webapps multiple "Mufaddal Masalawala"
2020-12-02 "ChurchCRM 4.2.0 - CSV/Formula Injection" webapps multiple "Mufaddal Masalawala"
2020-12-02 "Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit Profile" webapps multiple "Shahrukh Iqbal Mirza"
2020-12-02 "IDT PC Audio 1.0.6433.0 - 'STacSV' Unquoted Service Path" local windows "Manuel Alvarez"
Release Date Title Type Platform Author
2006-03-22 "1WebCalendar 4.0 - 'mainCal.cfm' SQL Injection" webapps cfm r0t3d3Vil
2006-03-22 "1WebCalendar 4.0 - 'viewEvent.cfm?EventID' SQL Injection" webapps cfm r0t3d3Vil
2006-03-22 "1WebCalendar 4.0 - '/news/newsView.cfm?NewsID' SQL Injection" webapps cfm r0t3d3Vil
2006-01-14 "EZDatabaseRemote 2.0 - PHP Script Code Execution" webapps php r0t3d3Vil
2005-12-30 "OOApp Guestbook 2.1 Home Script - Cross-Site Scripting" webapps php r0t3d3Vil
2005-12-30 "Kayako SupportSuite 3.0 0.26 - Multiple Cross-Site Scripting Vulnerabilities" webapps php r0t3d3Vil
2005-12-30 "Ades Design AdesGuestbook 2.0 Read Script - Cross-Site Scripting" webapps php r0t3d3Vil
2005-12-27 "FatWire UpdateEngine 6.2 - Multiple Cross-Site Scripting Vulnerabilities" webapps java r0t3d3Vil
2005-12-26 "Jax Calendar 1.34 - 'jax_calendar.php' SQL Injection" webapps php r0t3d3Vil
2005-12-25 "CS-Cart - Multiple SQL Injections" webapps php r0t3d3Vil
2005-12-25 "EZ Invoice Inc. EZI 2.0 - 'Invoices.php' SQL Injection" webapps php r0t3d3Vil
2005-12-25 "LogicBill 1.0 - Multiple SQL Injections" webapps php r0t3d3Vil
2005-12-23 "PaperThin CommonSpot Content Server 4.5 - Cross-Site Scripting" webapps cfm r0t3d3Vil
2005-12-22 "Tangora Portal CMS 4.0 - 'Action' Cross-Site Scripting" webapps asp r0t3d3Vil
2005-12-21 "Commercial Interactive Media SCOOP! 2.3 - 'lostPassword.asp' Multiple Cross-Site Scripting Vulnerabilities" webapps asp r0t3d3Vil
2005-12-21 "ComputerOil Redakto CMS 3.2 - Multiple Cross-Site Scripting Vulnerabilities" webapps cgi r0t3d3Vil
2005-12-21 "OpenEdit 4.0 - Results.HTML Cross-Site Scripting" webapps jsp r0t3d3Vil
2005-12-21 "Commercial Interactive Media SCOOP! 2.3 - 'category.asp' Multiple Cross-Site Scripting Vulnerabilities" webapps asp r0t3d3Vil
2005-12-21 "Commercial Interactive Media SCOOP! 2.3 - 'articleZone.asp?Invalid' Cross-Site Scripting" webapps asp r0t3d3Vil
2005-12-21 "Commercial Interactive Media SCOOP! 2.3 - 'prePurchaserRegistration.asp?Invalid' Cross-Site Scripting" webapps asp r0t3d3Vil
2005-12-21 "Quantum Art QP7.Enterprise - 'news_and_events_new.asp?p_news_id' SQL Injection" webapps asp r0t3d3Vil
2005-12-21 "Sitekit CMS 6.6 - 'Default.aspx' Multiple Cross-Site Scripting Vulnerabilities" webapps asp r0t3d3Vil
2005-12-21 "Sitekit CMS 6.6 - 'Request-call-back.html?ClickFrom' Cross-Site Scripting" webapps asp r0t3d3Vil
2005-12-21 "Sitekit CMS 6.6 - 'registration-form.html?ClickFrom' Cross-Site Scripting" webapps asp r0t3d3Vil
2005-12-21 "Commercial Interactive Media SCOOP! 2.3 - 'articleSearch.asp' Cross-Site Scripting" webapps asp r0t3d3Vil
2005-12-21 "Scoop 1.1 RC1 - Missing Story Error Cross-Site Scripting" webapps php r0t3d3Vil
2005-12-21 "Papoo 2.1.2 - 'index.php?menuid' SQL Injection" webapps php r0t3d3Vil
2005-12-21 "Papoo 2.1.2 - 'print.php' Multiple SQL Injections" webapps php r0t3d3Vil
2005-12-21 "SyntaxCMS - Search Query Cross-Site Scripting" webapps php r0t3d3Vil
2005-12-21 "PHPSlash 0.8.1 - 'article.php' SQL Injection" webapps php r0t3d3Vil
import requests
response = requests.get('http://127.0.0.1:8181?format=json')

For full documentation follow the link above

Cipherscan. Find out which SSL ciphersuites are supported by a target.

Identify and fingerprint Web Application Firewall (WAF) products protecting a website.