lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Tue, 29 Apr 2003 13:57:05 +0100 From: "Rui Pimenta" <rui.pimenta@...l.telepac.pt> To: <bugtraq@...urityfocus.com> Subject: Re: PTNews v1.7.7 - Access to administrator functions without authentification Update: Create News: URL Exploitable Replace Nnews: URL Exploitable Edit News: URL Exploitable It's just a matter of learning the indexing structures. ----- Original Message ----- From: "scrap" <webmaster@...uriteinfo.com> To: <bugtraq@...urityfocus.com> Sent: Monday, April 21, 2003 9:49 PM Subject: PTNews v1.7.7 - Access to administrator functions without authentification [snip] Function / URL : Create a news / Not an URL : only posted datas. Not impossible to exploit :) Replace a news / Not an URL : only posted datas. Not impossible to exploit :) Delete all news / http://www.victim.com/ptnews/ index.php?delete=all Edit a news / Too difficult to exploit http://www.openbg.net/ptsite/
Powered by blists - more mailing lists