header-logo
Suggest Exploit
vendor:
Community Software
by:
Sid3^effects aKa HaRi
9,3
CVSS
HIGH
SQL Injection and Persistent XSS
89 (SQL Injection) and 79 (XSS)
CWE
Product Name: Community Software
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: No
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010

Sijio Community Software SQLi/Persistent XSS Vulnerability

The vulnerability is a SQL injection vulnerability in the 'parent' parameter of the 'gallery' page. An attacker can inject malicious SQL code into the parameter to gain access to the database. The vulnerability also includes a persistent XSS vulnerability in the blog section. An attacker can register and post malicious XSS code in the blog section, which will be executed when the main page is accessed.

Mitigation:

Input validation should be used to prevent SQL injection attacks. Additionally, output encoding should be used to prevent XSS attacks.
Source

Exploit-DB raw data:

########################################################
#   I'm SiD3^effects member from Inj3ct0r Team         #
#    Support e-mail  : submit[at]inj3ct0r.com          #
########################################################
Name : Sijio Community Software SQLi/Persistent XSS Vulnerability
Date : july, 7 2010
Critical Level 	: HIGH
Vendor Url : http://www.sijio.com/
Google Dork: © Powered by sijio - Community Software
Author : Sid3^effects aKa HaRi <shell_c99[at]yahoo.com>
special thanks to : r0073r (inj3ct0r.com),L0rd CruSad3r,MaYur,MA1201,KeDar,Sonic,gunslinger_
greetz to :www.topsecure.net ,All ICW members and my friends :) luv y0 guyz 
#######################################################################################################
Xploit:SQLi Vulnerability 

DEMO URL : http://server/gallery/?parent=[SQLi]
########################################################################################################
Xploit:Persistent XSS Vulnerability

 The following script has persistent xss vuln in the blog section. 
Step 1: Register :D 

Step 2: Goto your blog section and post your new evil blog :P

Demo url :http://server/my_blogs/

Post your evil xss content in the blog section and the url is http://www.axlex.com/edit_blog/

Attack Pattern :">><marquee><h1>XSS3d By Sid3^effects</h1><marquee> 
Step 3 : Now goto the main page,check the blog section and the url is http://www.axlex.com/blogs/ and find your evil script:P
 
The attacker can injected evil xss script in the blog section :D 
########################################################################################################
# 0day no more 
# Sid3^effects