Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  [SA22607] Hosting Controller Multiple Vulnerabilities

  PwsPHP <= 1.1 (themes/fin.
php) Remote File Include Vulnerablity

  [Full-disclosure] Cross Site Scripting (XSS) Vulnerability in Web Mail platform by "Mirapoint"

  [Full-disclosure] Cross Site Scripting (XSS) Vulnerability in "ViewImage.
asp" by Daronet Internet Solutions

From:Rapigator <rapigator_(at)_yahoo.com>
Date:02.11.2006
Subject:[Full-disclosure] Invision Power Board 2.1.7 debug mode vulnerability

Debug mode is a feature in IPB 2.0.0-2.1.7 that shows
all database queries for each forum page requested.

If Debug mode is turned on, it is possible for anyone
to request a forgotten password for an account, and
capture the validation key that is sent to the
account's email address. This allows an attacker to
change anyone's password without having access to the
email account.

Through debug mode, it is also possible to bypass
captcha protection used to block bot actions(such as
automated registration), and table names can also be
discovered.

Debug mode is turned off by default, yet there are no
security warnings regarding this feature. It is best
to keep it off at all times.



_________________________________________________________________________________
___
Everyone is raving about the all-new Yahoo! Mail
(http://advision.webevents.yahoo.com/mailbeta/)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru