Exploit free cms

Page 2 of 2 FirstFirst 12
Results 16 to 24 of 24
  1. #16
    Developer PremiumEye is offline
    MemberRank
    Nov 2011 Join Date
    NetherlandsLocation
    550Posts

    Re: Exploit free cms

    Quote Originally Posted by Quackster View Post
    XSS isn't an SQL injection

    It means

    Code:
    cross site scripting
    I didn't say it's the same. I only wanted to give an example of another hack posibility

    Quote Originally Posted by r63 View Post
    SQL and XSS are two different things. Using Mysql real escape string doesn't fully protect you against code injection either. You also need to remove all html tags using strip-tags.
    I know. I never said it's the same. I only wanted to give an example of another hack posibility

  2. #17
    Check http://arcturus.pw The General is offline
    DeveloperRank
    Aug 2011 Join Date
    7,607Posts

    Re: Exploit free cms

    Quote Originally Posted by FlyHotel View Post
    Thank you :D The cms is uploading without SWFs and c_images, i will post the download link here when its done.

    EDIT:

    Upload is done without SWFs and c_images. Downloadlink; https://mega.co.nz/#!OY4DnLYa!TbydMR...6UPIARzUmI_a64

    I hope you can find the exploits for me, really thank you that you do this for me.
    Why is it still 167 mb? A regular CMS is nothing more than 30 mb...

  3. #18
    Keep your head up. FlyHotel is offline
    MemberRank
    Apr 2011 Join Date
    The NetherlandsLocation
    570Posts

    Re: Exploit free cms

    Quote Originally Posted by tdid View Post
    Why is it still 167 mb? A regular CMS is nothing more than 30 mb...
    The CMS has big files thats why it is 167 mb

    Quote Originally Posted by r63 View Post
    I could fuck your site up using JavaScript if you don't clear HTML tags, if you don't know what HTML tags are I suggest you start learning.
    I'm removing al the </html> tags do i have to remove this to; <?php echo stripslashes(htmlspecialchars($room['caption'])); ?> ??

  4. #19
    Account Upgraded | Title Enabled! r63 is offline
    MemberRank
    Jan 2012 Join Date
    apt-get GPSLocation
    430Posts

    Re: Exploit free cms

    Quote Originally Posted by FlyHotel View Post

    I'm removing al the </html> tags
    Idiot.

  5. #20
    Developer PremiumEye is offline
    MemberRank
    Nov 2011 Join Date
    NetherlandsLocation
    550Posts

    Re: Exploit free cms

    Quote Originally Posted by FlyHotel View Post
    I'm removing al the </html> tags do i have to remove this to; <?php echo stripslashes(htmlspecialchars($room['caption'])); ?> ??
    Do you understand anything about html/php/css/mysql?

  6. #21
    Developer Quackster is online now
    DeveloperRank
    Dec 2010 Join Date
    AustraliaLocation
    3,474Posts

    Re: Exploit free cms

    Quote Originally Posted by PremiumEye View Post
    Do you understand anything about html/php/css/mysql?
    You only need to understand PHP. In this case MySQL and CSS are irrelevant.

    /le sigh. humanity has failed.

  7. #22
    Keep your head up. FlyHotel is offline
    MemberRank
    Apr 2011 Join Date
    The NetherlandsLocation
    570Posts

    Re: Exploit free cms

    Quote Originally Posted by PremiumEye View Post
    Do you understand anything about html/php/css/mysql?
    A little bit not enough to make perfect stuff.

  8. #23
    Account Upgraded | Title Enabled! r63 is offline
    MemberRank
    Jan 2012 Join Date
    apt-get GPSLocation
    430Posts

    Re: Exploit free cms

    Quote Originally Posted by FlyHotel View Post
    A little bit not enough to make perfect stuff.
    Write <script type="text/javascript">alert("idk");</script> into any search bar or input field in your CMS and you should understand what I mean. I am writing this on my phone so if I've missed any < > or "s that's why.

  9. #24
    Banned V for Vendetta is offline
    BannedRank
    Feb 2007 Join Date
    1,809Posts

    Re: Exploit free cms

    I don't see a point of using such HTML tags, onto such CMS. Just makes it clear obvious that it's full of Exploits and that the whole title is just misleading.



Page 2 of 2 FirstFirst 12

Advertisement