Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  Open Conference Systems = 2.8.2 Remote File Inclusion

  AdMentor (banners) admin SQL injection

  local Calendar System v1.1 (lcStdLib.
inc) Remote File Include

  Full Disclosure:  Arbitrary Code Execution in LedgerSMB CVE-2006-5872

From:Hackers Center Security Group <DoZ_(at)_hackerscenter.com>
Date:28.01.2007
Subject:PHP Membership Manager Cross-Site Scripting Vulnerability

PHP Membership Manager Cross-Site Scripting Vulnerability


PHP Membership Manager is a browser based tool which allows a site owner to easily manage an unlimited
number of username / password accounts and groups which access secure, protected areas of a web site
which require logging in before accessing.


This issue is due to a failure in the application to properly sanitize user-supplied input. Attackers
may exploit this issue via a web client. This may help the attacker steal cookie-based authentication
credentials and launch other attacks. A successful exploit could allow an attacker to compromise the
application, access or modify data, or exploit vulnerabilities in the underlying database
implementation.




Hackers Center Security Group (http://www.hackerscenter.com)
Credit: Doz


Remote: NO
Local: Yes
Class: Input Validation Error



vendor: www.interactive-scripts.com
version: v1.5



Exploit: Manager Panel admin.php

Example: www.site.com/path/php_mm1.4/admin.php?_p=XSS=_approval_users

Online Demo: www.interactive-scripts.com/php_mm/demo.html

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server