Document Title:
===============
x10 Adult Media Script - Persistent Web Vulnerabilities
References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=301
Release Date:
=============
2011-10-31
Vulnerability Laboratory ID (VL-ID):
====================================
301
Product & Service Introduction:
===============================
Adult Media Script is an easy to use, easy to navigate, adult video script loaded with features!
After ordering you can have your site up and running in minutes.
(Copy of the Vendor Homepage: http://www.x10media.com/products-and-scripts/php-scripts/adult-media-script)
Abstract Advisory Information:
==============================
The vulnerability-lab researcher (Meister) discovered multiple persistent remote vulnerabilities on the x10 Adult Media script cms.
Vulnerability Disclosure Timeline:
==================================
2011-11-01: Public or Non-Public Disclosure
Discovery Status:
=================
Published
Affected Product(s):
====================
Exploitation Technique:
=======================
Remote
Severity Level:
===============
High
Technical Details & Description:
================================
Multiple persistent cross site scripting vulnerabilities are detected on the x10 Adult Media Script.
The bugs allows an remote attacker to inplement malicious persistent script codes on main modules of the software.
The successful exploitation of the vulnerability allows a remote attacker to hijack
users and admins sessions, manipulate profile content requests, redirect to external targets(websites) & can
lead to malware infiltration.
Vulnerable Module(s):
[+] Submit video - Title/Description
[+] Admin panel - Videos - Title/Description
[+] Admin panel - Settings - Advertisements
Picture(s):
../1.png
Proof of Concept (PoC):
=======================
The vulnerabilities can be exploited by remote attackers. For demonstration or reproduce ...
Code Review: [Index]