header-logo
Suggest Exploit
vendor:
Joomla com_community
by:
Sid3^effects aKa HaRi
7,5
CVSS
HIGH
Persistent XSS
79
CWE
Product Name: Joomla com_community
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010

Joomla com_community Persistent Xss Vulnerability

A persistent XSS vulnerability exists in Joomla com_community component. An attacker can exploit this vulnerability by registering as a user and setting their status to a malicious payload. This payload will be executed in the browser of any user who views the profile page of the attacker.

Mitigation:

Ensure that user input is properly sanitized and validated before being used in the application.
Source

Exploit-DB raw data:

1               ##########################################             1
0               I'm Sid3^effects member from Inj3ct0r Team             1
1               ##########################################             0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1

Name : Joomla com_community Persistent Xss Vulnerability
Date : june, 21 2010
Critical Level 	: HIGH
Vendor Url : http://styleware.eu/
DEMO URL :http://bizweb.styleware.eu/
Google Dork:inurl:com_community
Author : Sid3^effects aKa HaRi <shell_c99[at]yahoo.com>
special thanks to : r0073r (inj3ct0r.com),L0rd CruSad3r,MaYur,MA1201,KeDar,gunslinger_
greetz to :www.topsecure.net ,All ICW members and my friends :) luv y0 guyz 
#######################################################################################################

Xploit: Persistent Xss  Vulnerability

STEP 1: Register as a user :)

STEP 2: GOTO your profile and you can set your status ;)

STEP 3: For demo use  ">><marquee><h1>XSS3d By Sid3^effects</h1><marquee>

DEMO URL : http://server/index.php?option=com_community&view=profile&Itemid=66

###############################################################################################################
# 0day no more 
# Sid3^effects