what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

CS-Forum-0.81.txt

CS-Forum-0.81.txt
Posted Jun 14, 2006
Site acid-root.new.fr

CS-Forum 0.81 and prior suffer from XSS, Full path disclosure and SQL injection flaws.

tags | advisory, sql injection
SHA-256 | 7d7546f688e7b3250812cd4180b1350d36de5342664f6cc7445018a54aa7910e

CS-Forum-0.81.txt

Change Mirror Download
Cross Site Scripting
********************
http://[...]/read.php?msg_result=[XSS]
http://[...]/read.php?rep_titre=">[XSS]
Cookies: CSForum_nom=">[XSS]; CSForum_mail=">[XSS]; CSForum_url=">[XSS]

SQL Injection
*************
http://[...]/read.php?id=1'[SQL_SELECT]&debut=[SQL_LIMIT]
http://[...]/index.php?search=%'[SQL_SELECT]%23
http://[...]/index.php?debut=1[SQL] //Digit -> Without quote

Full Path Disclosure
********************
http://[...]/index.php?readall=&collapse[]= //setcookie()


Solution
********
SQL Injection => addslashes() / intval()
Cross Site Scripting => htmlentities()
Full Path Disclosure => is_string()


Credits
*******
by DarkFig -- http://www.acid-root.new.fr/advisories/csforum081.txt


Changelog
*********
[06-06-11] -- Vendor contacted
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    0 Files
  • 8
    Nov 8th
    0 Files
  • 9
    Nov 9th
    0 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close