So Today We Will talk About Some Advance In XSS phpFox (ajax.php) XSS Vulnerability
PhpFox is a Php Script For Making Social Networking website,
3.1 and some other versions of PhpFox are vulnerable For XSS.



Google Dork :"intext:© · English (US) Powered By phpFox Version 3.0.1."
 "inurl:/static/ajax.php?core"
Open any website for search results with text :© · English (US) Powered By phpFox Version 3.0.1
or url xyz.com/static/ajax.php?core
now You'll Get something Like This URL give below

http://www.xyz/static/ajax.php?core[ajax]=true&core[call]=core.message&height=150&width=300&message=<div class="error_message">some message here&core[security_token]=99d754d2b583565369e194e30eaabcbc

Now Chnage the Text &Message= Error....  (you have to replace the red text with your html Tags)
To see Example

Click On Below "Go Here" linkGo Here 
For example 2 Click On below"Example 2" link
Example 2
And Thats It
Leave Commentsss If some Problem
30 Dec 2012

Post a Comment

Emoticon
:) :)) ;(( :-) =)) ;( ;-( :d :-d @-) :p :o :>) (o) [-( :-? (p) :-s (m) 8-) :-t :-b b-( :-# =p~ $-) (b) (f) x-) (k) (h) (c) cheer
Click to see the code!
To insert emoticon you must added at least one space before the code.

 
Top