Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  phpPC 1.04 Multiples Remote File Inclusion

  Pearl Forums 2.4 Multiple Remote File Include Vulnerabilities

  PhotoCart 3.9 (adminprint.
php) Remote File Include Vulnerability

  Vulnerability in PostNuke

From:laurent gaffié <saps.audit_(at)_gmail.com>
Date:22.11.2006
Subject:JiRos Links Manager[injection sql & xss permanent]

vendor site:http://www.jiros.net/
product:JiRos Links Manager
bug: injection sql & xss
risk : medium


injection sql:
/openlink.asp?LinkID='[sql]
/viewlinks.asp?CategoryID='[sql]


xss permanent (post):
in: /submitlink.asp
-Link Name:
-Link URL:
-Link Image:
-Link Description:

those xss are really dangerous , because an admin need to approuve the link
so he gone get his cookie stealed direcly when he log into the administration panel

laurent gaffié & benjamin mossé
http://s-a-p.ca/
contact: saps.audit@gmail.com

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru