lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Fri, 9 Jul 2010 17:00:04 +0300 From: "MustLive" <mustlive@...security.com.ua> To: <bugtraq@...urityfocus.com> Subject: Vulnerabilities in SimpNews Hello Bugtraq! I want to warn you about security vulnerabilities in SimpNews. ----------------------------- Advisory: Vulnerabilities in SimpNews ----------------------------- URL: http://websecurity.com.ua/4245/ ----------------------------- Affected products: SimpNews V2.47.03 and previous versions. ----------------------------- Timeline: 26.10.2009 - found vulnerabilities. 29.05.2010 - announced at my site. 30.05.2010 - informed developer. 31.05.2010 - developer released SimpNews v2.48. In version 2.48 the developer fixed all mentioned vulnerabilities. 09.07.2010 - disclosed at my site. ----------------------------- Details: These are Full path disclosure and Cross-Site Scripting vulnerabilities. Full path disclosure: http://site/simpnews/news.php?lang=1&layout=layout2&sortorder=0&category=1 XSS: http://site/simpnews/news.php?layout=%3Cscript%3Ealert(document.cookie)%3C/script%3E http://site/simpnews/news.php?lang=en&layout=layout2&sortorder=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E Best wishes & regards, MustLive Administrator of Websecurity web site http://websecurity.com.ua
Powered by blists - more mailing lists