[<prev] [next>] [day] [month] [year] [list]
Message-ID: <52E83831.10905@securatary.com>
Date: Tue, 28 Jan 2014 15:07:29 -0800
From: Mark Litchfield <mark@...uratary.com>
To: webappsec@...urityfocus.com, bugtraq@...urityfocus.com,
vuln-dev@...urityfocus.com, pen-test@...urityfocus.com
Subject: Vulnerabilities within Mura CMS / Sitecore MCS / SmarterMail
These vulnerabilities allow for a complete take over giving full
administrative access as well as remote shells on the servers that they
are installed on.
Each of these suffer from Insecure Direct Object Reference Vulnerabilities.
Due to the details of the attack and screen shots, they can be found at
http://www.securatary.com/vulnerabilities
All the best
Mark Litchfield
Powered by blists - more mailing lists