Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  BJ Webring XSS

  WordPress source code compromised to enable remote code execution

  Remote File Include In DBImageGallery

From:CorryL <corrado.liotta_(at)_alice.it>
Date:03.03.2007
Subject:Tyger Bug Tracking System Multiple Vulnerability

-=[--------------------ADVISORY-------------------]=-
                                             
           Tyger Bug Tracking System     
                                              
 Author: CorryL    [corryl80@gmail.com]   
-=[-----------------------------------------------]=-


-=[+] Application:    Tyger Bug Tracking System
-=[+] Version:        1.1.3
-=[+] Vendor's URL:   http://uk.homeunix.org/tyger/cms/
-=[+] Platform:       Windows\Linux\Unix
-=[+] Bug type:       Cross-Site Script\Sql injection
-=[+] Exploitation:   Remote
-=[-]
-=[+] Author:           CorryL  ~ corryl80[at]gmail[dot]com ~
-=[+] Reference:       www.xoned.net
-=[+] Virtual Office:  http://www.kasamba.com/CorryL
-=[+] Irc Chan:         irc.darksin.net #x0n3-h4ck        


..::[ Descriprion ]::..

Tyger Bug tracking software has been designed and
developed or individuals or groups of software developers
to manage software development better.
By using Tyger teams of developers are able to communicate far better
with each fellow developers or end user's which ultimately improves the quality of
your software project or product.




..::[ Proof Of Concept ]::..

[Sql injection]

http://remote_server/ViewBugs.php?s=[sql]&o=ASC


[Xss]

http://remote_server/Login.php/>">[XSS]

http://remote_server/Register.php/>">[XSS]


About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server